Professional Data EngineerManaging and securing dataEasy

A financial institution is migrating its on-premises data warehouse to Google Cloud. They have stringent compliance requirements that mandate all sensitive data at rest must be encrypted with customer-managed encryption keys (CMEK), and the keys themselves must be generated and stored within FIPS 140-2 Level 3 certified hardware security modules (HSMs). Which Google Cloud Key Management Service (KMS) key type should they provision to meet these requirements for their data stored in services like BigQuery and Cloud Storage?

  1. ACloud KMS Vault keys
  2. BExternal keys (Cloud EKM)
  3. CSoftware keys
  4. DHardware keys (HSM)
Show answer & explanation

Correct answer: D. Hardware keys (HSM)

Hardware keys (HSM) in Cloud KMS are specifically designed to meet FIPS 140-2 Level 3 compliance by processing cryptographic operations within hardware security modules, which is a direct requirement for the financial institution.

Why the other options are wrong

  • A. Cloud KMS Vault keys is not a standard Google Cloud KMS key type.
  • B. External keys use keys managed outside Google Cloud, which doesn't guarantee FIPS 140-2 Level 3 compliance within GCP's boundary.
  • C. Software keys are stored in software, not FIPS 140-2 Level 3 certified hardware.

Cloud KMS Hardware Keys (HSM)

A type of Customer-Managed Encryption Key (CMEK) in Google Cloud KMS where cryptographic operations are performed within FIPS 140-2 Level 3 certified hardware security modules.

  • Provides the highest level of assurance for key protection.
  • Meets strict regulatory compliance requirements (e.g., FIPS 140-2 Level 3).
  • Keys are never extractable from the HSM.

Memory trick: Software is fast, HSM is secure, External is outside, but for FIPS Level 3, Hardware is the way to be.

More Managing and securing data questions