Professional Cloud Security EngineerEnsuring data protectionHard

A global enterprise needs to ensure that all data stored in Cloud Storage, BigQuery, and Cloud SQL databases is encrypted at rest using encryption keys that are centrally managed and rotated according to a consistent organizational policy. They want to avoid managing individual keys for each service and instead apply a default, consistent encryption standard across new resources. Which Cloud KMS feature, when integrated with these services, best addresses this need?

  1. ACloud KMS default key for a project or folder
  2. BCloud KMS key rings with specific key purposes
  3. CCustomer-Supplied Encryption Keys (CSEK)
  4. DCloud External Key Manager (EKM)
Show answer & explanation

Correct answer: A. Cloud KMS default key for a project or folder

Configuring a Cloud KMS default key at the project or folder level allows new resources created in supported services (like Cloud Storage, BigQuery, Cloud SQL) to automatically use that specified customer-managed encryption key (CMEK) for encryption at rest. This centralizes key management and ensures consistent application of the organizational encryption policy without manual configuration for each resource.

Why the other options are wrong

  • B. Key rings organize keys but don't automatically apply them as a default across services without an explicit default key configuration.
  • C. CSEK requires providing a key for each object/resource manually, which is not suitable for a default, consistent approach across many services.
  • D. Cloud EKM involves managing keys externally, which doesn't directly provide a 'default' key within Google Cloud's infrastructure for automatic application.

Cloud KMS Default Key

A Cloud KMS feature that allows you to specify a default Customer-Managed Encryption Key (CMEK) at the project or folder level, which is then automatically applied to new resources in supported Google Cloud services.

  • Simplifies CMEK adoption across an organization.
  • Ensures consistent encryption policy enforcement.
  • Reduces manual configuration for new resources.

Memory trick: Set a default key, and new resources will just pick it up.

More Ensuring data protection questions