ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 136 - Professional Cloud Security Engineer discussion

Report
Export

Your security team uses encryption keys to ensure confidentiality of user data. You want to establish a process to reduce the impact of a potentially compromised symmetric encryption key in Cloud Key Management Service (Cloud KMS).

Which steps should your team take before an incident occurs? (Choose two.)

A.
Disable and revoke access to compromised keys.
Answers
A.
Disable and revoke access to compromised keys.
B.
Enable automatic key version rotation on a regular schedule.
Answers
B.
Enable automatic key version rotation on a regular schedule.
C.
Manually rotate key versions on an ad hoc schedule.
Answers
C.
Manually rotate key versions on an ad hoc schedule.
D.
Limit the number of messages encrypted with each key version.
Answers
D.
Limit the number of messages encrypted with each key version.
E.
Disable the Cloud KMS API.
Answers
E.
Disable the Cloud KMS API.
Suggested answer: B, D

Explanation:

As per document 'Limiting the number of messages encrypted with the same key version helps prevent attacks enabled by cryptanalysis.' https://cloud.google.com/kms/docs/key-rotation

asked 18/09/2024
Herr Eylem Bulut
46 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first