A data engineering team is building a pipeline to process sensitive customer data. They need to ensure that the data is encrypted at rest and in transit, and that access to the data is strictly controlled based on user roles and data classifications. They also need to be able to audit all data access. Which combination of Google Cloud services would best meet these security and compliance requirements?
- ACloud SQL with default encryption, network security policies, and Cloud Monitoring.
- BCloud Storage with Customer-Managed Encryption Keys (CMEK), IAM, and Cloud Audit Logs.
- CBigQuery with default encryption, IAM, and Security Command Center.
- DCloud Storage with default encryption, IAM, and Cloud Audit Logs.
Show answer & explanationAnswer & explanation
Correct answer: B. Cloud Storage with Customer-Managed Encryption Keys (CMEK), IAM, and Cloud Audit Logs.
Using Cloud Storage with CMEK provides encryption at rest with customer control over encryption keys, which is often a strong compliance requirement. IAM provides granular access control based on roles, and Cloud Audit Logs record all administrative activities and data access events, fulfilling the auditing requirement. This combination addresses all specified security and compliance needs for sensitive data.
Why the other options are wrong
- A. Cloud SQL is for relational databases, not general data storage, and Cloud Monitoring focuses on performance and availability, not security auditing of access events.
- C. BigQuery is for analytics; while it has strong security, the question implies general storage and access control, where Cloud Storage with CMEK is more universally applicable for raw sensitive data.
- D. Default encryption is good but CMEK offers greater control, which is often needed for sensitive data compliance.
Secure Data Handling with CMEK, IAM, and Audit Logs
This combination provides robust security for sensitive data on Google Cloud: encryption at rest with customer key control (CMEK), granular access management (IAM), and comprehensive logging of data access and administrative actions (Cloud Audit Logs).
- CMEK provides customer control over encryption keys for data at rest.
- IAM enables fine-grained role-based access control.
- Cloud Audit Logs record all access and admin activities for compliance and forensics.
Memory trick: Keys, Roles, and Logs: The KRL of data security.