Professional Cloud ArchitectDesign for security and complianceHard

A large enterprise is building a data lake on Google Cloud using Cloud Storage and BigQuery. They need to ensure that all data stored in these services is encrypted at rest using customer-supplied encryption keys (CSEK) for specific highly sensitive datasets, allowing them to manage their own encryption keys directly. They want to avoid using Google-managed or customer-managed encryption keys (CMEK) for these particular datasets, as their compliance framework mandates direct key control. How can this requirement be met for Cloud Storage?

  1. AEnable default encryption for the Cloud Storage bucket.
  2. BProvide an encryption key directly with each Cloud Storage API request.
  3. CConfigure Cloud KMS to generate and manage keys for Cloud Storage.
  4. DUse VPC Service Controls to enforce key usage.
Show answer & explanation

Correct answer: B. Provide an encryption key directly with each Cloud Storage API request.

Customer-supplied encryption keys (CSEK) for Cloud Storage require the customer to provide an AES-256 encryption key with each API request for data operations (read/write). This gives the customer direct control over the key's lifecycle, meeting the strict compliance requirement.

Why the other options are wrong

  • A. Default encryption for Cloud Storage uses Google-managed encryption keys (GMEK) or CMEK, which does not meet the 'customer-supplied' requirement.
  • C. Cloud KMS manages CMEK, but the requirement specifically states avoiding CMEK and Google-managed keys.
  • D. VPC Service Controls create security perimeters and do not directly manage or enforce the type of encryption key (CSEK vs. CMEK) used for data at rest.

Customer-Supplied Encryption Keys (CSEK) for Cloud Storage

CSEK allows users to provide their own AES-256 encryption key for Cloud Storage objects, which must be supplied with each API request, giving direct control over the encryption key.

  • Customer manages the key entirely, not Google or Cloud KMS.
  • Key is provided with each read/write operation for an object.
  • Offers maximum control for specific compliance needs.

Memory trick: Keys: Google, Customer-Managed, or Customer-Supplied.

More Design for security and compliance questions