ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 34 - Professional Cloud Security Engineer discussion

Report
Export

Your company is using Cloud Dataproc for its Spark and Hadoop jobs. You want to be able to create, rotate,

and destroy symmetric encryption keys used for the persistent disks used by Cloud Dataproc. Keys can be stored in the cloud.

What should you do?

A.
Use the Cloud Key Management Service to manage the data encryption key (DEK).
Answers
A.
Use the Cloud Key Management Service to manage the data encryption key (DEK).
B.
Use the Cloud Key Management Service to manage the key encryption key (KEK).
Answers
B.
Use the Cloud Key Management Service to manage the key encryption key (KEK).
C.
Use customer-supplied encryption keys to manage the data encryption key (DEK).
Answers
C.
Use customer-supplied encryption keys to manage the data encryption key (DEK).
D.
Use customer-supplied encryption keys to manage the key encryption key (KEK).
Answers
D.
Use customer-supplied encryption keys to manage the key encryption key (KEK).
Suggested answer: B

Explanation:

This PD and bucket data is encrypted using a Google-generated data encryption key (DEK) and key encryption key (KEK). The CMEK feature allows you to create, use, and revoke the key encryption key (KEK). Google still controls the data encryption key (DEK). For more information on Google data encryption keys, see Encryption at Rest. https://cloud.google.com/dataproc/docs/concepts/configuring-clusters/customer-managed-encryption

https://codelabs.developers.google.com/codelabs/encrypt-and-decrypt-data-with-cloud-kms#0

asked 18/09/2024
Yucel Cetinkaya
43 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first