GCP PCA · Question 26 · Domain 3: Designing for Security and Compliance
Your company has a strict policy that all cryptographic keys used to encrypt data in Google Cloud must be generated and managed on-premises by your own Hardware Security Module (HSM). Which encryption method must you use?
Answer options:
Google-Managed Encryption Keys
Customer-Managed Encryption Keys (CMEK)
Customer-Supplied Encryption Keys (CSEK)
Cloud HSM
50 questions · hints · full answers · grading