Professional Cloud ArchitectDesign for security and complianceEasy
A large enterprise is migrating its on-premises applications to Google Cloud. They have a strict regulatory requirement to encrypt all data at rest, including database backups and object storage, using customer-managed encryption keys (CMEK) and ensure that key access is auditable. Which Google Cloud service should be used to manage these encryption keys to meet these requirements?
- AKey Access Justifications
- BCloud DLP
- CSecret Manager
- DCloud KMS
Show answer & explanationAnswer & explanation
Correct answer: D. Cloud KMS
Cloud Key Management Service (KMS) is specifically designed for managing cryptographic keys in Google Cloud, supporting CMEK and integrating with Cloud Audit Logs for auditable key access. Secret Manager is for secrets like API keys or passwords, not cryptographic keys for data encryption. Cloud DLP is for data loss prevention, and Key Access Justifications provides justifications for key access, but doesn't manage the keys themselves.
Why the other options are wrong
- A. Key Access Justifications provides a mechanism to receive and approve justifications when Google personnel access customer keys, but it does not manage the keys themselves.
- B. Cloud DLP (Data Loss Prevention) is used to discover, classify, and protect sensitive data, not to manage encryption keys.
- C. Secret Manager is used for storing and managing sensitive configuration data such as API keys, passwords, and certificates, not for managing cryptographic keys used to encrypt data at rest.
Cloud Key Management Service (Cloud KMS)
A cloud-hosted key management service that lets you manage cryptographic keys for your cloud services in the same way you manage keys on-premises.
- Manages symmetric and asymmetric encryption keys.
- Integrates with many Google Cloud services for CMEK.
- Provides audit logging for key usage.
Memory trick: Keys in the Cloud, Secure and Sound, Audited All Around.