Google Cloud Digital LeaderGeneral knowledge of Google CloudHard
A large enterprise wants to ensure that all data stored in Google Cloud Storage is encrypted at rest by default, without requiring any customer-managed keys or additional configuration. They need to meet basic security compliance requirements for data protection. Which encryption method is automatically applied to all Google Cloud Storage data and meets this requirement?
- AGoogle-Managed Encryption Keys (GMEK)
- BCustomer-Supplied Encryption Keys (CSEK)
- CClient-Side Encryption
- DCustomer-Managed Encryption Keys (CMEK)
Show answer & explanationAnswer & explanation
Correct answer: A. Google-Managed Encryption Keys (GMEK)
Google-Managed Encryption Keys (GMEK) is the default encryption method for all data at rest in Google Cloud Storage. Data is automatically encrypted using keys managed by Google, requiring no additional customer configuration and meeting basic compliance for data protection.
Why the other options are wrong
- B. CSEK requires the customer to provide and manage encryption keys, which goes against 'without requiring any customer-managed keys or additional configuration'.
- C. Client-side encryption encrypts data before it reaches Google Cloud, requiring customer implementation and management.
- D. CMEK allows customers to manage their own keys through Cloud Key Management Service, which requires configuration and management.
Google Cloud Storage Encryption
Google Cloud Storage encrypts all data at rest by default using Google-Managed Encryption Keys (GMEK), with options for customer-managed keys.
- GMEK is the default, automatic encryption for all data at rest.
- CSEK allows customers to provide their own keys.
- CMEK uses Cloud KMS for customer-managed keys, offering more control.
Memory trick: Encryption Options: Google-Managed is Default, Customer-Managed for Control, Customer-Supplied for External.