Professional Cloud Security EngineerEnsuring data protectionEasy

A global media company uses Cloud Storage to store high-resolution video assets. They need to ensure that all newly uploaded video files are automatically encrypted with customer-managed encryption keys (CMEK) from a specific Cloud KMS key ring, and that this encryption cannot be bypassed. How should they configure their Cloud Storage buckets to meet this requirement?

  1. ASet a default object ACL for the bucket to enforce CMEK.
  2. BApply an Organization Policy constraint to enforce CMEK for all Cloud Storage buckets.
  3. CUse a Cloud Functions trigger to re-encrypt objects with CMEK after upload.
  4. DConfigure the bucket's default encryption to use the specified CMEK key.
Show answer & explanation

Correct answer: D. Configure the bucket's default encryption to use the specified CMEK key.

Configuring the bucket's default encryption to use a specified CMEK key ensures that all new objects uploaded to that bucket are automatically encrypted with CMEK. This setting also prevents uploads of unencrypted objects or objects encrypted with Google-managed keys.

Why the other options are wrong

  • A. Object ACLs control access, not encryption at rest.
  • B. Organization Policies can enforce CMEK, but the question asks how to configure the *bucket* specifically, and setting default encryption on the bucket is the direct method.
  • C. Cloud Functions would be a reactive solution, which is not ideal for preventing unencrypted uploads initially.

Cloud Storage Default CMEK

A Cloud Storage bucket setting that automatically encrypts all new objects uploaded to the bucket with a specified Customer-Managed Encryption Key (CMEK), preventing uploads of objects encrypted with other methods.

  • Applies to new objects uploaded to the bucket.
  • Enforces a specific Cloud KMS key for encryption.
  • Prevents bypassing CMEK by disallowing other encryption types.

Memory trick: For storage security, set the default key, or risk a breach, you see!

More Ensuring data protection questions