Professional Data EngineerManaging and securing dataHard

A gaming company uses Cloud Spanner for its global leaderboard, which stores player IDs and high scores. To comply with privacy regulations, they need to ensure that player IDs are pseudonymized when used for analytics, but can be reversed to their original form for customer support purposes. The pseudonymization process must be consistent across all systems and securely managed. Which Google Cloud service should be used to manage this reversible pseudonymization?

  1. ACloud Data Loss Prevention (DLP) API
  2. BSecret Manager
  3. CCloud Key Management Service (KMS)
  4. DCloud Identity and Access Management (IAM)
Show answer & explanation

Correct answer: C. Cloud Key Management Service (KMS)

Cloud Key Management Service (KMS) can be used to manage symmetric encryption keys. These keys can then be used by applications to encrypt (pseudonymize) and decrypt (reverse pseudonymize) sensitive data like player IDs, ensuring consistency and secure key management.

Why the other options are wrong

  • A. Cloud DLP can de-identify data, but its primary focus is on one-way pseudonymization or redaction, not typically for reversible pseudonymization where the original value is needed back.
  • B. Secret Manager stores secrets like API keys or passwords, not for performing cryptographic operations like reversible encryption/decryption of data.
  • D. IAM manages access to resources, not cryptographic operations for data pseudonymization.

Reversible Pseudonymization with KMS

Reversible pseudonymization using Cloud KMS involves encrypting sensitive identifiers with a symmetric encryption key managed by KMS. This allows the data to be de-identified for analytics while retaining the ability to decrypt it back to its original form for specific use cases.

  • Uses symmetric encryption keys from KMS.
  • Applications perform encryption/decryption using the key.
  • Ensures consistent pseudonymization across systems.

Memory trick: Keys Can Securely Convert, Keep Reversible.

More Managing and securing data questions