Google Cloud Digital LeaderSecurity and operations with Google CloudHard

A healthcare provider is moving patient data to Google Cloud. Due to strict regulatory requirements (e.g., HIPAA), they must ensure that all sensitive data at rest in Cloud Storage buckets is encrypted with customer-managed encryption keys (CMEK) and that access to these keys is tightly controlled and auditable. Which Google Cloud service should they use to manage and protect these encryption keys?

  1. AIdentity and Access Management (IAM)
  2. BCloud Storage
  3. CCloud Key Management Service (KMS)
  4. DSecret Manager
Show answer & explanation

Correct answer: C. Cloud Key Management Service (KMS)

Cloud Key Management Service (KMS) is a cloud-hosted key management service that lets you manage cryptographic keys for your cloud services. It's designed for managing CMEK, providing strong controls over key access, usage, and auditing, which is critical for compliance with regulations like HIPAA.

Why the other options are wrong

  • A. IAM controls who can access KMS keys, but KMS is the service that manages the keys themselves.
  • B. Cloud Storage stores the data, but relies on other services for key management when CMEK is used.
  • D. Secret Manager is for storing API keys, passwords, and other secrets, not primarily for managing cryptographic encryption keys used for data at rest.

Cloud Key Management Service (KMS)

Cloud KMS is a cloud-hosted key management service that lets you manage cryptographic keys for your cloud services and provides strong controls over key access and usage.

  • Supports various key types (symmetric, asymmetric) and purposes (encryption, signing).
  • Integrates with many Google Cloud services for CMEK.
  • Offers robust access control, auditing, and key rotation capabilities.

Memory trick: KMS Keeps Keys Secure for Compliance.

More Security and operations with Google Cloud questions