Google Associate Cloud EngineerEnsuring successful operation of a cloud solutionHard
A finance application running on Compute Engine instances needs to store sensitive customer data, which requires strong encryption at rest. The company's security policy also mandates that encryption keys must be managed by the customer and stored in a FIPS 140-2 Level 3 validated hardware security module (HSM). Which Google Cloud encryption option should be utilized?
- ACustomer-managed encryption keys (CMEK) with Cloud KMS
- BCloud HSM with Cloud KMS
- CGoogle-managed encryption keys
- DCustomer-supplied encryption keys (CSEK)
Show answer & explanationAnswer & explanation
Correct answer: B. Cloud HSM with Cloud KMS
Cloud HSM, integrated with Cloud KMS, provides a FIPS 140-2 Level 3 validated hardware security module for managing encryption keys. This directly meets the requirement for customer-managed keys stored in an HSM with that specific validation level.
Why the other options are wrong
- A. CMEK with Cloud KMS allows customer management, but standard Cloud KMS keys are software-backed and do not inherently provide FIPS 140-2 Level 3 HSM validation without explicitly using Cloud HSM.
- C. Google-managed encryption keys do not allow the customer to manage the keys, violating the policy.
- D. CSEK means the customer provides the encryption key directly to Google Cloud services, but Google Cloud does not manage the key lifecycle or provide HSM backing for it.
Cloud HSM
A fully managed cloud-hosted hardware security module (HSM) service that allows you to generate, store, and manage cryptographic keys in FIPS 140-2 Level 3 validated HSMs.
- Integrates with Cloud KMS for key management.
- Provides the highest level of key protection and regulatory compliance.
- Keys are stored in dedicated hardware modules, not software.
Memory trick: HSM: Hardware Secures Mandated Keys.