Professional Cloud ArchitectAnalyze and optimize technical and business processesHard
A healthcare provider is building a new application on Google Cloud that processes sensitive patient data. This application must comply with strict regulatory requirements (e.g., HIPAA) regarding data encryption, access controls, and auditing. The application will use Cloud Storage for data at rest and Cloud KMS for key management. To ensure compliance, which specific Cloud Storage encryption option should be chosen to allow the customer to maintain maximum control over the encryption keys and meet regulatory auditing requirements for key usage?
- AGoogle-managed encryption keys (Customer-Managed Encryption Keys, CMEK) with Cloud KMS.
- BGoogle-managed encryption keys (default encryption at rest).
- CServer-side encryption with Google-managed encryption keys (SSE-C).
- DCustomer-supplied encryption keys (CSEK) with keys provided directly in API requests.
Show answer & explanationAnswer & explanation
Correct answer: A. Google-managed encryption keys (Customer-Managed Encryption Keys, CMEK) with Cloud KMS.
Customer-Managed Encryption Keys (CMEK) with Cloud KMS allows the customer to create, manage, and control the lifecycle of their encryption keys within Cloud KMS. This provides maximum control over the keys, including rotation, permissions, and auditing of key usage, which is crucial for meeting strict regulatory requirements like HIPAA for sensitive data.
Why the other options are wrong
- B. Google-managed encryption keys (default encryption) are controlled entirely by Google and do not provide the customer with the necessary control or auditing capabilities over key usage to meet strict regulatory requirements.
- C. Server-side encryption with Google-managed encryption keys (SSE-C) is not a Google Cloud offering. Google-managed encryption keys are the default, while SSE-C is for customer-supplied keys that are provided with each request, which is not the same as CMEK.
- D. Customer-supplied encryption keys (CSEK) require the customer to manage and provide keys with every API request, which can be operationally complex and doesn't offer the centralized key management and auditing capabilities of Cloud KMS that are often required for compliance.
Cloud Storage Encryption Options
Cloud Storage offers various encryption options, including Google-managed, customer-managed (CMEK), and customer-supplied (CSEK), each providing different levels of control over encryption keys.
- Default encryption uses Google-managed keys.
- CMEK allows customers to manage keys in Cloud KMS, offering high control and auditing.
- CSEK requires customers to supply keys with each request.
- CMEK is often preferred for regulatory compliance due to enhanced key control.
Memory trick: CMEK: Control My Encryption Keys, for Audit's sake!