Professional Data EngineerManaging and securing dataHard
A data engineering team is building a data pipeline that ingests sensitive customer data from various sources into BigQuery. They need to ensure that the encryption keys used for this data are highly secure and meet stringent compliance requirements, including FIPS 140-2 Level 3. Which type of Cloud Key Management Service (KMS) key should they use?
- AExternal keys (CMEK with external key manager)
- BHardware Security Module (HSM) keys
- CSoftware keys
- DCloud EKM keys
Show answer & explanationAnswer & explanation
Correct answer: B. Hardware Security Module (HSM) keys
Hardware Security Module (HSM) keys in Cloud KMS are backed by FIPS 140-2 Level 3 certified HSMs, providing the highest level of security and meeting the stringent compliance requirement.
Why the other options are wrong
- A. External keys (Cloud EKM) allow keys to be managed outside Google Cloud, but the question specifies the *type* of key within KMS, and HSM directly addresses FIPS 140-2 Level 3.
- C. Software keys are stored and processed in software, offering a lower security assurance level than HSMs.
- D. Cloud EKM refers to External Key Management, where the key material is outside Google Cloud. While it offers control, HSM keys are specifically designed for the FIPS 140-2 Level 3 certification requirement within Cloud KMS.
Cloud KMS HSM Keys
Cloud KMS HSM keys are cryptographic keys generated and stored in FIPS 140-2 Level 3 certified Hardware Security Modules (HSMs) within Google Cloud, offering the highest level of security assurance.
- Backed by physical HSMs.
- FIPS 140-2 Level 3 certified.
- Provides tamper-proof key storage and operations.
Memory trick: KMS Keys Keep High Security.