Professional Cloud Security EngineerEnsuring data protectionEasy
A global media company uses Cloud Storage to store high-resolution video assets. They need to ensure that all newly uploaded video files are automatically encrypted with customer-managed encryption keys (CMEK) from a specific Cloud KMS key ring, and that this encryption cannot be bypassed. How should they configure their Cloud Storage buckets to meet this requirement?
- ASet a default object ACL for the bucket to enforce CMEK.
- BApply an Organization Policy constraint to enforce CMEK for all Cloud Storage buckets.
- CUse a Cloud Functions trigger to re-encrypt objects with CMEK after upload.
- DConfigure the bucket's default encryption to use the specified CMEK key.
Show answer & explanationAnswer & explanation
Correct answer: D. Configure the bucket's default encryption to use the specified CMEK key.
Configuring the bucket's default encryption to use a specified CMEK key ensures that all new objects uploaded to that bucket are automatically encrypted with CMEK. This setting also prevents uploads of unencrypted objects or objects encrypted with Google-managed keys.
Why the other options are wrong
- A. Object ACLs control access, not encryption at rest.
- B. Organization Policies can enforce CMEK, but the question asks how to configure the *bucket* specifically, and setting default encryption on the bucket is the direct method.
- C. Cloud Functions would be a reactive solution, which is not ideal for preventing unencrypted uploads initially.
Cloud Storage Default CMEK
A Cloud Storage bucket setting that automatically encrypts all new objects uploaded to the bucket with a specified Customer-Managed Encryption Key (CMEK), preventing uploads of objects encrypted with other methods.
- Applies to new objects uploaded to the bucket.
- Enforces a specific Cloud KMS key for encryption.
- Prevents bypassing CMEK by disallowing other encryption types.
Memory trick: For storage security, set the default key, or risk a breach, you see!