Google Associate Cloud EngineerDeploying and implementing a cloud solutionMedium

A company is deploying a new application that processes sensitive customer data. Due to strict compliance requirements, all data at rest in Cloud Storage buckets must be encrypted with customer-managed encryption keys (CMEK), and the keys must be rotated annually. Which Google Cloud service integrates with Cloud Storage to manage these encryption keys?

  1. ACloud Key Management Service (KMS)
  2. BCloud IAM
  3. CSecret Manager
  4. DCloud Audit Logs
Show answer & explanation

Correct answer: A. Cloud Key Management Service (KMS)

Cloud Key Management Service (KMS) allows you to manage cryptographic keys, including customer-managed encryption keys (CMEK) for Cloud Storage, and supports key rotation as required by compliance.

Why the other options are wrong

  • B. Cloud IAM manages access control to resources, not the encryption keys themselves.
  • C. Secret Manager stores API keys, passwords, and other secrets, but not the cryptographic keys used for data encryption at rest in services like Cloud Storage.
  • D. Cloud Audit Logs records administrative activities and data access, not for managing encryption keys.

Cloud Key Management Service (KMS)

A cloud-hosted key management service that lets you manage cryptographic keys for your cloud services and applications.

  • Supports symmetric and asymmetric encryption keys.
  • Integrates with many Google Cloud services for CMEK.
  • Provides key rotation, auditing, and access control.

Memory trick: KMS for encryption keys, Secret Manager for secrets, IAM for access.

More Deploying and implementing a cloud solution questions