ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 233 - Professional Cloud Security Engineer discussion

Report
Export

You manage a mission-critical workload for your organization, which is in a highly regulated industry The workload uses Compute Engine VMs to analyze and process the sensitive data after it is uploaded to Cloud Storage from the endpomt computers. Your compliance team has detected that this workload does not meet the data protection requirements for sensitive data. You need to meet these requirements;

* Manage the data encryption key (DEK) outside the Google Cloud boundary.

* Maintain full control of encryption keys through a third-party provider.

* Encrypt the sensitive data before uploading it to Cloud Storage

* Decrypt the sensitive data during processing in the Compute Engine VMs

* Encrypt the sensitive data in memory while in use in the Compute Engine VMs

What should you do?

Choose 2 answers

A.
Create a VPC Service Controls service perimeter across your existing Compute Engine VMs and Cloud Storage buckets
Answers
A.
Create a VPC Service Controls service perimeter across your existing Compute Engine VMs and Cloud Storage buckets
B.
Migrate the Compute Engine VMs to Confidential VMs to access the sensitive data.
Answers
B.
Migrate the Compute Engine VMs to Confidential VMs to access the sensitive data.
C.
Configure Cloud External Key Manager to encrypt the sensitive data before it is uploaded to Cloud Storage and decrypt the sensitive data after it is downloaded into your VMs
Answers
C.
Configure Cloud External Key Manager to encrypt the sensitive data before it is uploaded to Cloud Storage and decrypt the sensitive data after it is downloaded into your VMs
D.
Create Confidential VMs to access the sensitive data.
Answers
D.
Create Confidential VMs to access the sensitive data.
E.
Configure Customer Managed Encryption Keys to encrypt the sensitive data before it is uploaded to Cloud Storage, and decrypt the sensitive data after it is downloaded into your VMs.
Answers
E.
Configure Customer Managed Encryption Keys to encrypt the sensitive data before it is uploaded to Cloud Storage, and decrypt the sensitive data after it is downloaded into your VMs.
Suggested answer: C, D

Explanation:

https://cloud.google.com/confidential-computing/confidential-vm/docs/creating-cvm-instance#considerations

Confidential VM does not support live migration. You can only enable Confidential Computing on a VM when you first create the instance. https://cloud.google.com/confidential-computing/confidential-vm/docs/creating-cvm-instance


asked 18/09/2024
Roberto Ramadhin
32 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first