Professional Cloud Security EngineerEnsuring data protectionMedium
A global banking institution is migrating its core financial applications to Google Cloud. They require that all encryption keys for sensitive customer data are generated and used within a FIPS 140-2 Level 3 certified hardware security module (HSM) and that the cryptographic operations are performed within this secure boundary. The institution prefers to manage these keys directly within Google Cloud's infrastructure but with strong assurances of hardware-backed security. Which Cloud KMS key protection level should they choose?
- AEXTERNAL
- BSOFTWARE
- CEXTERNAL_VPC
- DHSM
Show answer & explanationAnswer & explanation
Correct answer: D. HSM
The HSM key protection level in Cloud KMS ensures that keys are generated and used within FIPS 140-2 Level 3 certified hardware security modules. This meets the requirement for hardware-backed security and cryptographic operations within a secure boundary, while still allowing the keys to be managed within Google Cloud's infrastructure.
Why the other options are wrong
- A. EXTERNAL keys (Cloud EKM) are managed outside of Google Cloud, which contradicts the 'managed directly within Google Cloud's infrastructure' preference.
- B. SOFTWARE keys are not hardware-backed and do not meet the FIPS 140-2 Level 3 HSM requirement.
- C. EXTERNAL_VPC is a specific type of EKM connection and still involves external key management, not direct management within Google Cloud's KMS infrastructure.
Cloud KMS Key Protection Levels
Cloud KMS offers different protection levels for cryptographic keys, determining how and where the key material is stored and cryptographic operations are performed.
- SOFTWARE: Keys stored in software.
- HSM: Keys stored in hardware security modules (FIPS 140-2 Level 3).
- EXTERNAL: Keys managed by an external key manager (Cloud EKM).
Memory trick: Software for speed, HSM for strength, External for sovereignty.