Google Cloud Digital LeaderSecurity and operations with Google CloudMedium

A healthcare organization is migrating patient records to Google Cloud and requires strong encryption for data at rest and in transit. They also need to ensure that the cryptographic keys are managed securely and comply with industry regulations like HIPAA. Which Google Cloud service should they use to manage these encryption keys?

  1. ACloud SQL
  2. BCloud Key Management Service (KMS)
  3. CSecret Manager
  4. DCloud Storage
Show answer & explanation

Correct answer: B. Cloud Key Management Service (KMS)

Cloud Key Management Service (KMS) is specifically designed for managing cryptographic keys, offering a centralized, highly available, and secure solution for encryption, which is crucial for sensitive data and regulatory compliance.

Why the other options are wrong

  • A. Cloud SQL is a relational database service; it uses KMS for encryption but doesn't manage the keys itself.
  • C. Secret Manager stores API keys, passwords, and other sensitive configuration data, but not primarily cryptographic keys for encrypting large datasets.
  • D. Cloud Storage stores data, but KMS manages the encryption keys for that data.

Cloud Key Management Service (KMS)

Cloud KMS is a cloud-hosted key management service that lets you manage cryptographic keys for your cloud services in a single, centralized cloud service.

  • Manages symmetric and asymmetric encryption keys.
  • Integrates with other Google Cloud services for data encryption.
  • Offers hardware security module (HSM) and external key management options.
  • Supports audit logging for key usage.

Memory trick: KMS keeps your keys safe and sound.

More Security and operations with Google Cloud questions