Google Associate Cloud EngineerDeploying and implementing a cloud solutionMedium
A company is deploying a new application that processes sensitive customer data. Due to strict compliance requirements, all data at rest in Cloud Storage buckets must be encrypted with customer-managed encryption keys (CMEK), and the keys must be rotated annually. Which Google Cloud service integrates with Cloud Storage to manage these encryption keys?
- ACloud Key Management Service (KMS)
- BCloud IAM
- CSecret Manager
- DCloud Audit Logs
Show answer & explanationAnswer & explanation
Correct answer: A. Cloud Key Management Service (KMS)
Cloud Key Management Service (KMS) allows you to manage cryptographic keys, including customer-managed encryption keys (CMEK) for Cloud Storage, and supports key rotation as required by compliance.
Why the other options are wrong
- B. Cloud IAM manages access control to resources, not the encryption keys themselves.
- C. Secret Manager stores API keys, passwords, and other secrets, but not the cryptographic keys used for data encryption at rest in services like Cloud Storage.
- D. Cloud Audit Logs records administrative activities and data access, not for managing encryption keys.
Cloud Key Management Service (KMS)
A cloud-hosted key management service that lets you manage cryptographic keys for your cloud services and applications.
- Supports symmetric and asymmetric encryption keys.
- Integrates with many Google Cloud services for CMEK.
- Provides key rotation, auditing, and access control.
Memory trick: KMS for encryption keys, Secret Manager for secrets, IAM for access.