ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 222 - Professional Cloud Security Engineer discussion

Report
Export

You are setting up a new Cloud Storage bucket in your environment that is encrypted with a customer managed encryption key (CMEK). The CMEK is stored in Cloud Key Management Service (KMS). in project 'pr j -a', and the Cloud Storage bucket will use project 'prj-b'. The key is backed by a Cloud Hardware Security Module (HSM) and resides in the region europe-west3. Your storage bucket will be located in the region europe-west1. When you create the bucket, you cannot access the key. and you need to troubleshoot why.

What has caused the access issue?

A.
A firewall rule prevents the key from being accessible.
Answers
A.
A firewall rule prevents the key from being accessible.
B.
Cloud HSM does not support Cloud Storage
Answers
B.
Cloud HSM does not support Cloud Storage
C.
The CMEK is in a different project than the Cloud Storage bucket
Answers
C.
The CMEK is in a different project than the Cloud Storage bucket
D.
The CMEK is in a different region than the Cloud Storage bucket.
Answers
D.
The CMEK is in a different region than the Cloud Storage bucket.
Suggested answer: D

Explanation:

When you use a customer-managed encryption key (CMEK) to secure a Cloud Storage bucket, the key and the bucket must be located in the same region. In this case, the key is in europe-west3 and the bucket is in europe-west1, which is why you're unable to access the key.

asked 18/09/2024
GIORGOS KELAIDIS
32 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first