Professional Data EngineerManaging and securing dataMedium
A data engineering team is building a data pipeline that ingests sensitive customer data from various sources into Cloud Storage. Due to strict regulatory requirements, all data at rest in Cloud Storage must be encrypted using customer-provided encryption keys (CSEK), where the keys are managed and supplied by the customer, not Google. Which encryption option should they configure for their Cloud Storage buckets and objects?
- ACustomer-supplied encryption keys (CSEK)
- BCloud KMS Hardware Security Module (HSM) keys
- CCustomer-managed encryption keys (CMEK)
- DGoogle-managed encryption keys
Show answer & explanationAnswer & explanation
Correct answer: A. Customer-supplied encryption keys (CSEK)
Customer-supplied encryption keys (CSEK) for Cloud Storage are specifically designed for scenarios where the customer manages and provides the encryption key for their data, fulfilling the requirement that keys are managed and supplied by the customer, not Google.
Why the other options are wrong
- B. Cloud KMS HSM keys are a type of CMEK, where keys are managed within Google Cloud KMS HSMs, not directly by the customer outside of Google's key management service.
- C. Customer-managed encryption keys (CMEK) use keys managed within Google Cloud KMS, but Google still manages the KMS service itself. The requirement states keys are 'managed and supplied by the customer, not Google'.
- D. Google-managed encryption keys are managed entirely by Google, not by the customer.
Cloud Storage Customer-Supplied Encryption Keys (CSEK)
A Google Cloud Storage encryption option where the customer generates and manages their own encryption keys and provides them to Google Cloud Storage for data encryption and decryption.
- Customer retains full control over key management.
- Keys are provided with each request to Cloud Storage.
- Offers the highest level of control over encryption keys.
Memory trick: Google keys easy, KMS keys managed, but Supplied keys are fully customer-handed.