QuestionQ4

Ingesting and processing the data

You have a BigQuery table that receives data directly from a Pub/Sub subscription. The ingested data is encrypted using a Google-managed encryption key. You must comply with a new organization policy requiring keys from a centralized Cloud Key Management Service (Cloud KMS) project to encrypt data at rest. What should you do?

Explanation

BigQuery supports customer-managed encryption keys (CMEK) from Cloud KMS for data at rest. Creating a CMEK-protected BigQuery table and migrating the old table’s data ensures the stored historical and destination data is protected by the centrally managed key; changing only the ingestion path or Pub/Sub topic does not re-encrypt the BigQuery table’s existing data.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!