Professional Cloud ArchitectManage and provision solution infrastructureEasy

A financial services company processes sensitive customer data and must adhere to strict regulatory compliance standards. They need to ensure that all data at rest in their Cloud Storage buckets is encrypted with customer-managed encryption keys (CMEK) and that access to these keys is tightly controlled. Which IAM role, at a minimum, is required for a service account to encrypt and decrypt objects using a CMEK key in Cloud KMS?

  1. Aroles/cloudkms.cryptoKeyEncrypterDecrypter
  2. Broles/cloudkms.admin
  3. Croles/cloudkms.viewer
  4. Droles/cloudkms.keyOperator
Show answer & explanation

Correct answer: A. roles/cloudkms.cryptoKeyEncrypterDecrypter

The `roles/cloudkms.cryptoKeyEncrypterDecrypter` role grants permission to encrypt and decrypt data using a specific Cloud KMS cryptographic key, which is exactly what a service account needs for CMEK operations with Cloud Storage.

Why the other options are wrong

  • B. This role grants administrative control over KMS keys, which is overly permissive for just encrypting/decrypting data.
  • C. This role only allows viewing KMS resources, not performing cryptographic operations.
  • D. This role manages key versions and rotation, but not the actual encryption/decryption of data.

Cloud KMS CMEK Roles

Specific IAM roles for Cloud Key Management Service (KMS) that control access to cryptographic keys for encryption and decryption operations.

  • CMEK allows customers to manage their own encryption keys.
  • Requires specific permissions for service accounts to use keys.
  • Different roles exist for viewing, administering, and using keys.

Memory trick: Encrypt/Decrypt with the Crypto Key Encrypter Decrypter.

More Manage and provision solution infrastructure questions