Professional Data EngineerManaging and securing dataEasy
A financial institution is implementing a new data warehousing solution on Google Cloud. They store highly sensitive customer financial data in BigQuery. Due to regulatory requirements, they must ensure that data at rest is encrypted with customer-managed encryption keys (CMEK), and these keys must be automatically rotated annually. Which Google Cloud service should they use to manage and automatically rotate these encryption keys for BigQuery?
- ACloud Storage
- BCloud Key Management Service (KMS)
- CSecret Manager
- DIdentity and Access Management (IAM)
Show answer & explanationAnswer & explanation
Correct answer: B. Cloud Key Management Service (KMS)
Cloud Key Management Service (KMS) is specifically designed for managing cryptographic keys, including customer-managed encryption keys (CMEK), and supports automatic key rotation, which aligns with the regulatory requirement for annual rotation.
Why the other options are wrong
- A. Cloud Storage is for storing objects, not for managing encryption keys.
- C. Secret Manager is for storing secrets like API keys and passwords, not primarily for cryptographic encryption keys with rotation policies.
- D. IAM manages access permissions to resources, not the encryption keys themselves.
Cloud KMS for CMEK
Cloud KMS is a Google Cloud service for managing cryptographic keys, including customer-managed encryption keys (CMEK), which can be used to encrypt data in other Google Cloud services.
- Supports symmetric and asymmetric keys.
- Integrates with many Google Cloud services for CMEK.
- Provides automatic key rotation policies.
Memory trick: Keys Keep Many Secrets Securely.