A payment processing company uses Cloud SQL for PostgreSQL to store transactional data, including customer payment details. Due to strict industry regulations (e.g., PCI DSS), all data at rest must be encrypted using customer-managed keys. The company wants to leverage Cloud KMS for key management to centralize key lifecycle and access control. How should the data engineering team configure Cloud SQL to meet this requirement?
- AImplement client-side encryption on the application before writing data to Cloud SQL.
- BConfigure Customer-Managed Encryption Keys (CMEK) for the Cloud SQL instance using Cloud KMS.
- CUse Cloud SQL's built-in encryption features without external key management.
- DEnable Google-Managed Encryption Keys (GMEK) for the Cloud SQL instance.
Show answer & explanationAnswer & explanation
Correct answer: B. Configure Customer-Managed Encryption Keys (CMEK) for the Cloud SQL instance using Cloud KMS.
Customer-Managed Encryption Keys (CMEK) for Cloud SQL directly addresses the requirement to encrypt data at rest using customer-managed keys, with the keys themselves being managed and controlled within Cloud KMS. This centralizes key lifecycle and access control while adhering to regulatory requirements.
Why the other options are wrong
- A. Client-side encryption adds significant complexity to the application layer and bypasses the native integration of Cloud SQL with Cloud KMS for at-rest encryption.
- C. Cloud SQL's built-in encryption by default uses GMEK; to use customer-managed keys, CMEK must be explicitly configured with Cloud KMS.
- D. GMEK uses keys managed by Google, which does not meet the requirement for customer-managed keys.
Cloud SQL with Customer-Managed Encryption Keys (CMEK)
Cloud SQL instances can be configured to use Customer-Managed Encryption Keys (CMEK) from Cloud Key Management Service (KMS). This allows customers to control the encryption keys used for their data at rest in Cloud SQL, providing enhanced security and meeting specific compliance requirements.
- Encrypts data at rest in Cloud SQL using keys from Cloud KMS.
- Customer controls key lifecycle, permissions, and rotation.
- Integrated directly with Cloud SQL for seamless encryption/decryption.
- Essential for compliance with regulations requiring customer key management.
Memory trick: SQL's data is safe with KMS's custom key.