Professional Cloud Security EngineerEnsuring data protectionMedium

A financial services company is migrating sensitive customer data to Google Cloud Storage. They need to ensure that all data at rest is encrypted using keys that are centrally managed within Google Cloud and that key access is auditable. They also require high availability and durability for these encryption keys. Which Cloud KMS key type should they use?

  1. ACustomer-supplied encryption keys (CSEK)
  2. BHardware-backed keys (Cloud HSM)
  3. CExternal keys (Cloud EKM)
  4. DSoftware-backed keys
Show answer & explanation

Correct answer: B. Hardware-backed keys (Cloud HSM)

Hardware-backed keys (Cloud HSM) in Cloud KMS provide a FIPS 140-2 Level 3 validated hardware security module for key generation and storage, ensuring high security, availability, and durability. Key access is centrally managed and auditable through Cloud KMS and Cloud Audit Logs.

Why the other options are wrong

  • A. Customer-supplied encryption keys (CSEK) require the customer to provide and manage keys for each operation, which doesn't align with 'centrally managed within Google Cloud' or 'high availability and durability' for the key itself via KMS.
  • C. External keys (Cloud EKM) provide customer control outside Google Cloud, but the requirement specifies 'centrally managed within Google Cloud'.
  • D. Software-backed keys are suitable for many use cases but do not meet the 'high security' implied by 'sensitive customer data' and the need for a hardware-backed solution.

Cloud KMS Hardware-backed Keys (Cloud HSM)

A Cloud KMS key type that uses FIPS 140-2 Level 3 validated Hardware Security Modules (HSMs) to generate, store, and perform cryptographic operations, offering enhanced security, high availability, and durability for encryption keys within Google Cloud.

  • Keys generated and stored in FIPS 140-2 Level 3 HSMs.
  • Offers strongest security guarantees for keys within GCP.
  • Integrated with Cloud KMS for central management and auditing.
  • Provides high availability and durability for keys.

Memory trick: For keys, choose your vault: Software, Hardware, or External's default!

More Ensuring data protection questions