Professional Cloud Security EngineerEnsuring data protectionEasy
A financial services company is migrating sensitive customer data to Google Cloud Storage. They need to ensure that data at rest is encrypted with customer-managed encryption keys (CMEK) and that access to these keys is highly controlled and auditable. Which Google Cloud service should they use to manage these encryption keys?
- ACloud Key Management Service (KMS)
- BCloud Identity and Access Management (IAM)
- CSecret Manager
- DData Loss Prevention (DLP)
Show answer & explanationAnswer & explanation
Correct answer: A. Cloud Key Management Service (KMS)
Cloud Key Management Service (KMS) is specifically designed for managing cryptographic keys, including customer-managed encryption keys (CMEK), providing a centralized, auditable, and highly available service for encryption operations. It integrates directly with Google Cloud Storage for data at rest encryption.
Why the other options are wrong
- B. IAM manages permissions and roles, not encryption keys themselves.
- C. Secret Manager stores secrets like API keys and passwords, not cryptographic encryption keys for data at rest.
- D. DLP identifies and protects sensitive data, but does not manage encryption keys.
Cloud Key Management Service (KMS)
A cloud-hosted key management service that lets you manage cryptographic keys for your cloud services in the same way you manage keys on-premises.
- Manages symmetric and asymmetric encryption keys.
- Integrates with many Google Cloud services for CMEK.
- Provides auditing and access control for keys.
Memory trick: KMS: Keeping My Secrets safe in the Cloud.