Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Google Professional Cloud Security Engineer Exam - Topic 1 Question 117 Discussion

You need to use Cloud External Key Manager to create an encryption key to encrypt specific BigQuery data at rest in Google Cloud. Which steps should you do first?
C) 1. Create or use an existing key with a unique uniform resource identifier (URI) in a supported external key management partner system.2. In the external key management partner system, grant access for this key to use your Google Cloud project.
A) 1. Create or use an existing key with a unique uniform resource identifier (URI) in your Google Cloud project.2. Grant your Google Cloud project access to a supported external key management partner system.
B) 1. Create or use an existing key with a unique uniform resource identifier (URI) in Cloud Key Management Service (Cloud KMS).2. In Cloud KMS, grant your Google Cloud project access to use the key.
D) 1. Create an external key with a unique uniform resource identifier (URI) in Cloud Key Management Service (Cloud KMS).2. In Cloud KMS, grant your Google Cloud project access to use the key.

Google Professional Cloud Security Engineer Exam - Topic 1 Question 117 Discussion

Actual exam question for Google's Professional Cloud Security Engineer exam
Question #: 117
Topic #: 1
[All Professional Cloud Security Engineer Questions]

You need to use Cloud External Key Manager to create an encryption key to encrypt specific BigQuery data at rest in Google Cloud. Which steps should you do first?

Show Suggested Answer Hide Answer
Suggested Answer: C

https://cloud.google.com/kms/docs/ekm#how_it_works

- First, you create or use an existing key in a supported external key management partner system. This key has a unique URI or key path.

- Next, you grant your Google Cloud project access to use the key, in the external key management partner system.

- In your Google Cloud project, you create a Cloud EKM key, using the URI or key path for the externally-managed key.


Contribute your Thoughts:

0/2000 characters
Vinnie
4 days ago
Wait, can you really use an external key manager? That's new to me!
upvoted 0 times
...
Lynelle
9 days ago
C sounds right, but I'm not sure about the external part.
upvoted 0 times
...
Cassandra
14 days ago
I think B is better, KMS is more integrated.
upvoted 0 times
...
Keith
19 days ago
Option A is the way to go!
upvoted 0 times
...
Mary
24 days ago
Definitely A), it's the most straightforward approach!
upvoted 0 times
...
Desirae
29 days ago
Wait, can we really trust external key management?
upvoted 0 times
...
Annabelle
1 month ago
C) sounds correct, but I'm not sure about the external partner system.
upvoted 0 times
...
Novella
1 month ago
I think B) is better since it uses Cloud KMS directly.
upvoted 0 times
...
Mollie
1 month ago
A) is the right choice for external key management.
upvoted 0 times
...
Santos
2 months ago
I’m a bit confused about whether we should use Cloud KMS or go straight to the external key management system. I need to double-check that part.
upvoted 0 times
...
Aliza
2 months ago
I feel like option C makes sense since it mentions using an external key management partner, which is what we need for Cloud External Key Manager.
upvoted 0 times
...
Cherrie
2 months ago
I remember practicing a similar question where we had to grant access to the project, but I can't recall if it was before or after creating the key.
upvoted 0 times
...
Corazon
4 months ago
I think the first step involves creating a key with a unique URI, but I'm not sure if it should be in Cloud KMS or an external system.
upvoted 0 times
...

Save Cancel