Professional Cloud ArchitectManage and provision solution infrastructureHard

A healthcare provider is storing patient records in Cloud Storage. Due to strict regulatory compliance (e.g., HIPAA), they need to ensure that all data at rest is encrypted with customer-managed encryption keys (CMEK) and that access to these keys is tightly controlled and auditable. Which Google Cloud service combination should be used to manage the encryption keys and enforce access policies?

  1. ACloud HSM with VPC Service Controls
  2. BCloud Key Vault with Access Transparency
  3. CCloud KMS with IAM and Cloud Audit Logs
  4. DCloud Storage default encryption with Organization Policy
Show answer & explanation

Correct answer: C. Cloud KMS with IAM and Cloud Audit Logs

Cloud Key Management Service (KMS) manages customer-managed encryption keys (CMEK) for Cloud Storage, providing centralized key control. IAM (Identity and Access Management) controls who can access and use these keys. Cloud Audit Logs provide a comprehensive audit trail of all key access and usage, fulfilling the strict compliance and auditable access requirements.

Why the other options are wrong

  • A. Cloud HSM is a service within Cloud KMS that provides hardware-backed keys, but 'Cloud HSM with VPC Service Controls' doesn't directly address the CMEK management, access control, and auditing requirements as comprehensively as KMS+IAM+Audit Logs. VPC Service Controls are for data exfiltration prevention, not key management and auditing.
  • B. Cloud Key Vault is not a Google Cloud service. Access Transparency provides logs of Google administrative access to customer data, which is different from auditing customer access to their own encryption keys.
  • D. Cloud Storage default encryption uses Google-managed encryption keys (CSEK-C or SSE-C). The requirement is for *customer-managed* encryption keys (CMEK). Organization Policy can enforce the use of CMEK, but it doesn't manage the keys or provide the access control and auditing mechanisms for the keys themselves.

CMEK with Cloud KMS, IAM, and Cloud Audit Logs

Customer-Managed Encryption Keys (CMEK) allow customers to use their own encryption keys managed within Cloud Key Management Service (KMS) for data at rest in Google Cloud services like Cloud Storage. IAM controls access to these keys, and Cloud Audit Logs provide an immutable record of all key usage for compliance and auditing.

  • Cloud KMS manages customer-provided encryption keys (CMEK)
  • IAM controls who can use, manage, or view key resources
  • Cloud Audit Logs record all administrative and data access events related to keys
  • Ensures strong control and audibility over encryption keys
  • Crucial for regulatory compliance (e.g., HIPAA, PCI DSS)

Memory trick: KMS keys, IAM guards, Audit Logs record all.

More Manage and provision solution infrastructure questions