Professional Cloud Security EngineerEnsuring data protectionEasy

A financial services company is migrating sensitive customer data to Google Cloud Storage. They need to ensure that data at rest is encrypted with customer-managed encryption keys (CMEK) and that access to these keys is highly controlled and auditable. Which Google Cloud service should they use to manage these encryption keys?

  1. ACloud Key Management Service (KMS)
  2. BCloud Identity and Access Management (IAM)
  3. CSecret Manager
  4. DData Loss Prevention (DLP)
Show answer & explanation

Correct answer: A. Cloud Key Management Service (KMS)

Cloud Key Management Service (KMS) is specifically designed for managing cryptographic keys, including customer-managed encryption keys (CMEK), providing a centralized, auditable, and highly available service for encryption operations. It integrates directly with Google Cloud Storage for data at rest encryption.

Why the other options are wrong

  • B. IAM manages permissions and roles, not encryption keys themselves.
  • C. Secret Manager stores secrets like API keys and passwords, not cryptographic encryption keys for data at rest.
  • D. DLP identifies and protects sensitive data, but does not manage encryption keys.

Cloud Key Management Service (KMS)

A cloud-hosted key management service that lets you manage cryptographic keys for your cloud services in the same way you manage keys on-premises.

  • Manages symmetric and asymmetric encryption keys.
  • Integrates with many Google Cloud services for CMEK.
  • Provides auditing and access control for keys.

Memory trick: KMS: Keeping My Secrets safe in the Cloud.

More Ensuring data protection questions