Professional Data EngineerEnsuring solution qualityEasy
A financial institution is implementing a data lake on Google Cloud. They need to ensure that all data at rest is encrypted, and they must have complete control over the encryption keys due to strict regulatory compliance requirements. The solution should also integrate seamlessly with Google Cloud services like Cloud Storage and BigQuery. Which Google Cloud service should they use to manage their encryption keys?
- AIdentity and Access Management (IAM)
- BSecret Manager
- CCloud Data Loss Prevention (DLP)
- DCloud Key Management Service (KMS)
Show answer & explanationAnswer & explanation
Correct answer: D. Cloud Key Management Service (KMS)
Cloud Key Management Service (KMS) is specifically designed for managing cryptographic keys, including customer-managed encryption keys (CMEK), which allows customers to control the keys used to encrypt their data at rest on Google Cloud. This directly addresses the requirement for complete control over encryption keys.
Why the other options are wrong
- A. IAM manages access permissions to resources, not the cryptographic encryption keys themselves.
- B. Secret Manager is for storing secrets like API keys and passwords, not for managing cryptographic encryption keys used for data at rest.
- C. Cloud DLP is used for discovering, classifying, and redacting sensitive data, not for managing encryption keys.
Cloud Key Management Service (KMS)
A cloud-hosted key management service that lets you manage cryptographic keys for your cloud services in the same way you manage keys on-premises.
- Supports symmetric and asymmetric encryption.
- Integrates with many Google Cloud services for CMEK.
- Provides auditing and access control for keys.
Memory trick: Keys Keep Cloud Secrets Safe.