Professional Cloud Security EngineerEnsuring data protectionHard
A global e-commerce company uses Cloud SQL for MySQL to store customer order data. They need to implement a solution to ensure that all data at rest in Cloud SQL is encrypted using keys that they fully control and manage outside of Google Cloud, with the ability to revoke access to the keys at any time. Which Cloud KMS feature, combined with Cloud SQL, should they use?
- ACustomer-Supplied Encryption Keys (CSEK) for Cloud SQL.
- BCustomer-Managed Encryption Keys (CMEK) via Cloud KMS.
- CCloud HSM keys integrated with Cloud SQL.
- DCloud External Key Manager (EKM) with Cloud KMS.
Show answer & explanationAnswer & explanation
Correct answer: D. Cloud External Key Manager (EKM) with Cloud KMS.
To achieve full control and management of encryption keys outside of Google Cloud, with the ability to revoke access at any time, Cloud External Key Manager (EKM) is the correct choice. EKM allows Google Cloud services to use keys residing in an external, customer-managed key management system, with Cloud KMS acting as an intermediary.
Why the other options are wrong
- A. Cloud SQL does not directly support Customer-Supplied Encryption Keys (CSEK) in the same way Cloud Storage does; it primarily uses CMEK or EKM for customer-controlled keys.
- B. CMEK keys are managed within Cloud KMS (Google Cloud), so the customer does not 'fully control and manage outside of Google Cloud'.
- C. Cloud HSM keys are managed within Google Cloud's FIPS 140-2 Level 3 validated HSMs, which are still within Google Cloud's infrastructure, not 'fully control and manage outside of Google Cloud'.
Cloud External Key Manager (EKM)
A Cloud KMS feature that allows Google Cloud services to encrypt data using keys managed in an external, third-party key management system outside of Google Cloud, providing customers with full control and the ability to revoke key access.
- Keys reside in an external KMS, not Google Cloud.
- Cloud KMS acts as an intermediary to use the external keys.
- Provides ultimate control over key lifecycle and revocation.
- Supported by services like Cloud SQL, Cloud Storage, BigQuery.
Memory trick: Who holds the key? Google, You, or an External friend, that's the encryption story's end!