Professional Data EngineerManaging and securing dataEasy
A data engineering team is building a data pipeline that ingests data from various sources into a Cloud Storage data lake. They need to ensure that all data at rest in the data lake is encrypted with keys that are centrally managed and controlled by the security team, and that the keys are protected by a FIPS 140-2 Level 3 validated hardware security module (HSM). Which Google Cloud service should be used to manage these encryption keys?
- ACloud Identity and Access Management (IAM) custom roles.
- BCloud Key Management Service (KMS) with a Hardware Security Module (HSM) key ring.
- CSecret Manager for storing encryption key material.
- DCloud Data Loss Prevention (DLP) for key management.
Show answer & explanationAnswer & explanation
Correct answer: B. Cloud Key Management Service (KMS) with a Hardware Security Module (HSM) key ring.
Cloud Key Management Service (KMS) is a dedicated service for managing encryption keys. Its HSM key type specifically offers FIPS 140-2 Level 3 validation, fulfilling the requirement for hardware-backed key protection.
Why the other options are wrong
- A. Cloud IAM manages permissions and access control, not encryption keys themselves.
- C. Secret Manager is for storing secrets like API keys or database credentials, not for managing cryptographic encryption keys used for data at rest.
- D. Cloud DLP is for discovering, classifying, and redacting sensitive data, not for managing encryption keys.
Cloud KMS HSM Keys
Cloud Key Management Service (KMS) provides various key types, including Hardware Security Module (HSM) keys, which are backed by FIPS 140-2 Level 3 validated HSMs for enhanced security and compliance.
- Manages cryptographic keys for various Google Cloud services.
- HSM keys offer strong, hardware-backed protection for encryption keys.
- Meets strict regulatory and compliance requirements.
- Integrates with other services like Cloud Storage for CMEK.
Memory trick: For keys so secure, KMS with HSM is the cure!