Professional Cloud Security EngineerEnsuring data protectionHard

An organization is migrating an on-premises application that uses a custom key management system (KMS) to Google Cloud. They want to integrate their existing KMS with Google Cloud services to manage encryption keys, ensuring that the keys never leave their on-premises environment while still being usable by Google Cloud services like Cloud Storage and BigQuery. Which Google Cloud KMS feature should they utilize?

  1. ACloud External Key Manager (EKM)
  2. BCloud HSM keys
  3. CCloud KMS asymmetric encryption keys
  4. DCloud KMS symmetric encryption keys
Show answer & explanation

Correct answer: A. Cloud External Key Manager (EKM)

Cloud External Key Manager (EKM) allows customers to use encryption keys that are managed in an external, on-premises (or other cloud) key management system while still performing cryptographic operations within Google Cloud services. This meets the requirement of keeping keys in the on-premises environment while enabling their use by Google Cloud services.

Why the other options are wrong

  • B. Cloud HSM keys are managed within Google Cloud's FIPS 140-2 Level 3 validated hardware, not on-premises.
  • C. Asymmetric encryption keys are managed within Cloud KMS, not externally.
  • D. Symmetric encryption keys are managed within Cloud KMS, not externally.

Cloud External Key Manager (EKM)

A Cloud KMS feature that allows Google Cloud services to use encryption keys managed in an external key management system, thus keeping the keys outside Google Cloud.

  • Keys remain in the customer's external KMS.
  • Google Cloud services can perform cryptographic operations using these keys.
  • Addresses strict regulatory requirements for key residency.

Memory trick: EKM: External Keys Managed, keeping them home, yet cloud-enabled.

More Ensuring data protection questions