Professional Cloud ArchitectManage implementationHard
A healthcare organization is building a new patient data analytics platform on Google Cloud. The platform will ingest sensitive patient health information (PHI) from various sources, process it, and store it in BigQuery. Due to strict regulatory compliance (e.g., HIPAA), they must ensure that all data, both in transit and at rest, is encrypted. Furthermore, the organization requires the ability to audit and control access to the encryption keys used for BigQuery data at rest. Which combination of Google Cloud security features should they implement?
- ACloud Armor for data in transit and Customer-Supplied Encryption Keys (CSEK) for data at rest.
- BClient-Side Encryption for data in transit and Default Encryption for data at rest.
- CCloud VPN for data in transit and Google-Managed Encryption Keys for data at rest.
- DTLS/SSL for data in transit and Customer-Managed Encryption Keys (CMEK) for data at rest.
Show answer & explanationAnswer & explanation
Correct answer: D. TLS/SSL for data in transit and Customer-Managed Encryption Keys (CMEK) for data at rest.
TLS/SSL ensures data in transit is encrypted, which is standard for secure communication over networks. Customer-Managed Encryption Keys (CMEK) for BigQuery allows the organization to control and audit the encryption keys used for data at rest, meeting the strict compliance requirements for PHI by separating key management from data storage.
Why the other options are wrong
- A. Cloud Armor is a WAF/DDoS protection service, not for generic data in transit encryption. CSEK (Customer-Supplied Encryption Keys) means the user provides the key directly, but CMEK (Customer-Managed) through Cloud Key Management Service offers better integration, auditing, and lifecycle management for compliance.
- B. Client-Side Encryption is generally for data prior to upload; GCP handles in-transit encryption. Default Encryption for data at rest uses Google-managed keys, which does not provide the required control and audit capabilities.
- C. Cloud VPN secures network tunnels, but TLS/SSL is the standard for application-level data in transit. Google-Managed Encryption Keys do not provide the required control and audit capabilities for compliance.
Data Encryption & Key Management on Google Cloud
Google Cloud provides various options for encrypting data in transit and at rest, including default encryption, customer-managed encryption keys (CMEK), and customer-supplied encryption keys (CSEK).
- Data in transit is encrypted by default using TLS/SSL.
- Data at rest is encrypted by default using Google-managed encryption keys.
- CMEK provides control over encryption keys for data at rest via Cloud KMS.
- CSEK allows users to provide their own encryption keys directly to services.
Memory trick: TLS secures PHI transit, CMEK locks its rest.