QuestionQ39

Ensuring data protection

You need to use Cloud External Key Manager to create an encryption key that encrypts specific BigQuery data at rest in Google Cloud. Which steps should you take first?

  • A
    1. Create or use an existing key with a unique uniform resource identifier (URI) in your Google Cloud project. 2. Grant your Google Cloud project access to a supported external key management partner system.
  • B
    1. Create or use an existing key with a unique uniform resource identifier (URI) in Cloud Key Management Service (Cloud KMS). 2. In Cloud KMS, grant your Google Cloud project access to use the key.
  • C
    1. Create or use an existing key with a unique uniform resource identifier (URI) in a supported external key management partner system. 2. In the external key management partner system, grant access for this key to use your Google Cloud project.
  • D
    1. Create an external key with a unique uniform resource identifier (URI) in Cloud Key Management Service (Cloud KMS). 2. In Cloud KMS, grant your Google Cloud project access to use the key.
Explanation

For a manually managed Cloud EKM key, the key is created or selected in a supported external key-management partner system, where it has a unique URI or key path. That partner system must grant the Google Cloud project access to use the key before Cloud KMS can create a Cloud EKM key version that references it.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!