ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 151 - Professional Cloud Security Engineer discussion

Report
Export

Your privacy team uses crypto-shredding (deleting encryption keys) as a strategy to delete personally identifiable information (PII). You need to implement this practice on Google Cloud while still utilizing the majority of the platform's services and minimizing operational overhead. What should you do?

A.
Use client-side encryption before sending data to Google Cloud, and delete encryption keys on-premises
Answers
A.
Use client-side encryption before sending data to Google Cloud, and delete encryption keys on-premises
B.
Use Cloud External Key Manager to delete specific encryption keys.
Answers
B.
Use Cloud External Key Manager to delete specific encryption keys.
C.
Use customer-managed encryption keys to delete specific encryption keys.
Answers
C.
Use customer-managed encryption keys to delete specific encryption keys.
D.
Use Google default encryption to delete specific encryption keys.
Answers
D.
Use Google default encryption to delete specific encryption keys.
Suggested answer: C

Explanation:

https://cloud.google.com/sql/docs/mysql/cmek

'You might have situations where you want to permanently destroy data encrypted with CMEK. To do this, you destroy the customer-managed encryption key version. You can't destroy the keyring or key, but you can destroy key versions of the key.'

asked 18/09/2024
Haider Nassiry
40 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first