Google Cloud Digital LeaderSecurity and operations with Google CloudMedium

A healthcare organization is migrating patient records to Google Cloud and requires strong encryption for data at rest. Due to strict compliance regulations, they must have exclusive control over the encryption keys and be able to rotate them on a schedule. Which Google Cloud service enables this level of key management and control?

  1. ACloud Storage encryption (Google-managed keys)
  2. BSecret Manager
  3. CCloud HSM
  4. DCloud Key Management Service (KMS)
Show answer & explanation

Correct answer: D. Cloud Key Management Service (KMS)

Cloud Key Management Service (KMS) allows customers to manage their own encryption keys for Google Cloud services, providing control over key creation, rotation, and access policies, which is essential for stringent compliance requirements.

Why the other options are wrong

  • A. Google-managed encryption keys are controlled by Google, not the customer, which doesn't meet the requirement for exclusive control.
  • B. Secret Manager stores secrets like API keys and passwords, not primarily for managing encryption keys for data at rest.
  • C. Cloud HSM provides hardware security module (HSM) based key management, which offers even stronger security but KMS is the more direct answer for customer control over keys and rotation for general data at rest.

Cloud Key Management Service (KMS)

Cloud KMS is a cloud-hosted key management service that allows you to manage cryptographic keys for your cloud services, providing customer control over key lifecycle and usage.

  • Manages symmetric and asymmetric encryption keys.
  • Integrates with many Google Cloud services.
  • Supports key rotation, versioning, and access control.
  • Available in software, hardware (HSM), and external (EKS) flavors.

Memory trick: KMS keeps your keys, granting full control.

More Security and operations with Google Cloud questions