Professional Cloud Security EngineerEnsuring data protectionEasy

A financial institution is storing sensitive customer transaction data in Google Cloud Storage buckets. Due to regulatory requirements, they must ensure that all deletions and modifications of this data are strictly prevented for a period of seven years, even by administrators. Which Cloud Storage feature should be configured to meet this compliance requirement?

  1. ABucket Lock
  2. BCustomer-Managed Encryption Keys (CMEK)
  3. CObject Versioning
  4. DSigned URLs
Show answer & explanation

Correct answer: A. Bucket Lock

Bucket Lock enforces a retention policy on all objects within a bucket, making them immutable and undeletable for a specified duration, even by the bucket owner or administrators, which directly addresses the regulatory requirement for preventing deletions and modifications.

Why the other options are wrong

  • B. CMEK encrypts data but does not prevent its deletion or modification.
  • C. Object Versioning keeps multiple versions of an object but does not prevent deletion of all versions or modifications of the current version.
  • D. Signed URLs provide temporary access to specific objects but do not enforce retention or immutability.

Cloud Storage Bucket Lock

A feature that allows you to configure a retention policy on a Cloud Storage bucket, preventing objects from being deleted or modified for a specified duration.

  • Enforces immutability on objects.
  • Protects against accidental or malicious deletion/modification.
  • Adheres to WORM (Write Once, Read Many) principles.

Memory trick: Lock your buckets to keep data forever, like a digital vault.

More Ensuring data protection questions