Professional Cloud Security EngineerEnsuring complianceHard
A research institution is using Google Cloud to process highly sensitive genomic data. They need to ensure that all data at rest in Cloud Storage buckets is encrypted with customer-managed encryption keys (CMEK) rather than Google-managed encryption keys, and that these keys are automatically rotated every 90 days. Additionally, they need to restrict key usage to specific service accounts. Which two Google Cloud services are essential to meet these requirements?
- AData Loss Prevention (DLP) API and Cloud Storage
- BSecret Manager and Cloud KMS
- CCloud Storage and Cloud IAM
- DCloud KMS and Cloud Storage
Show answer & explanationAnswer & explanation
Correct answer: D. Cloud KMS and Cloud Storage
Cloud KMS (Key Management Service) is used to create, manage, and rotate customer-managed encryption keys (CMEK). Cloud Storage can then be configured to use these CMEK keys for data at rest encryption, ensuring that the customer retains control over the encryption keys and their rotation. Cloud KMS also allows restricting key usage via IAM policies applied directly to the keys, fulfilling all requirements.
Why the other options are wrong
- A. DLP API focuses on data discovery and redaction, not on managing encryption keys for data at rest.
- B. Secret Manager stores secrets, but Cloud KMS is specifically for cryptographic keys and their lifecycle management, which is required for CMEK.
- C. While Cloud Storage stores the data and Cloud IAM manages permissions, IAM alone doesn't provide the key management and rotation capabilities needed for CMEK.
CMEK with Cloud KMS & Cloud Storage
Customer-Managed Encryption Keys (CMEK) leverage Cloud KMS to create, manage, and rotate encryption keys used by services like Cloud Storage for data at rest encryption, providing enhanced control over cryptographic material.
- Customer controls the encryption key lifecycle.
- Cloud KMS provides key management, rotation, and access control.
- Cloud Storage uses CMEK for data at rest encryption instead of Google-managed keys.
Memory trick: KMS for Keys, Storage for Data.