Professional Cloud Security EngineerEnsuring data protectionEasy

A financial institution is storing highly sensitive customer data in Google Cloud Storage. Due to strict regulatory compliance requirements, they need to ensure that data at rest is encrypted using keys that are managed and controlled exclusively within their own on-premises environment, while still leveraging Google Cloud Storage for scalability and durability. Which Google Cloud service should they use to meet this requirement?

  1. ACloud External Key Manager (EKM)
  2. BDefault Google-managed encryption keys
  3. CCloud HSM with customer-supplied encryption keys (CSEK)
  4. DCloud Key Management Service (KMS) with customer-managed encryption keys (CMEK)
Show answer & explanation

Correct answer: A. Cloud External Key Manager (EKM)

Cloud External Key Manager (EKM) allows organizations to encrypt data in Google Cloud using keys that are managed and stored outside of Google's infrastructure, meeting strict regulatory requirements for external key control.

Why the other options are wrong

  • B. Default Google-managed keys are fully controlled by Google and do not meet the requirement for exclusive on-premises key control.
  • C. CSEK means the customer provides the key material to Google, but Google still uses it within its infrastructure, and Cloud HSM is a Google-managed service.
  • D. CMEK uses keys managed within Cloud KMS, which is a Google-managed service, not exclusively on-premises.

Cloud External Key Manager (EKM)

Cloud EKM enables you to encrypt data in Google Cloud using encryption keys that you manage in a supported external key management system, outside of Google's infrastructure.

  • Keys remain outside Google Cloud.
  • Provides complete control over key lifecycle.
  • Suitable for stringent regulatory compliance.

Memory trick: External Keys Mean Ultimate Control Outside.

More Ensuring data protection questions