QuestionQ162

Ensuring data protection

You are assisting a client that intends to migrate its data to Google Cloud. You must recommend an encryption service to manage its encrypted keys. The requirements are:

  • The master key must rotate at least once every 45 days.
  • The solution that stores the master key must be validated at FIPS 140-2 Level 3.
  • For redundancy, the master key must be stored across multiple regions in the US.

Which solution satisfies these requirements?

  • A Customer-managed encryption keys with Cloud Key Management Service
  • B Customer-managed encryption keys with Cloud HSM
  • C Customer-supplied encryption keys
  • D Google-managed encryption keys
Explanation

Customer-managed encryption keys with Cloud HSM use FIPS 140-2 Level 3 validated hardware security modules. Cloud KMS provides customer-controlled automatic rotation schedules for HSM-backed symmetric keys, including a 45-day schedule. Cloud HSM keys can be created in a U.S. multi-region, whose key material is stored in multiple regional data centers for redundancy.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!