Google Cloud Digital LeaderSecurity and operations with Google CloudEasy
A global e-commerce company uses Google Cloud to host its customer-facing applications. They need to ensure that all data at rest in Cloud Storage buckets is encrypted with customer-managed keys (CMK) and that access to these keys is tightly controlled and audited. Which Google Cloud service should they primarily use to manage these encryption keys?
- ASecret Manager
- BCloud Key Management Service (KMS)
- CCloud Storage Transfer Service
- DCloud Identity and Access Management (IAM)
Show answer & explanationAnswer & explanation
Correct answer: B. Cloud Key Management Service (KMS)
Cloud Key Management Service (KMS) is specifically designed for managing cryptographic keys, including customer-managed encryption keys (CMEK) for services like Cloud Storage. It allows for key generation, storage, and access control, meeting the requirement for tight control and auditing.
Why the other options are wrong
- A. Secret Manager is used for storing API keys, passwords, certificates, and other sensitive configuration data, not primarily for cryptographic keys used for data encryption at rest.
- C. Cloud Storage Transfer Service is used for moving large amounts of data into or out of Cloud Storage, not for key management.
- D. IAM manages permissions and roles for users and services, not the cryptographic keys themselves.
Cloud Key Management Service (KMS)
A cloud-hosted key management service that lets you manage cryptographic keys for your cloud services in the same way you manage keys on-premises.
- Supports symmetric and asymmetric encryption.
- Integrates with many Google Cloud services for CMEK.
- Provides auditing and access control for keys.
Memory trick: Keys Keep Kritical Kargo Kovered.