GCP PCA · Question 48 · Security Design
Your organization is migrating sensitive data to Cloud Storage. The security team dictates that Google must not manage the encryption keys, but they also do not want the operational burden of maintaining their own highly available key servers on-premises. Which TWO actions should you take? (Select TWO)
Answer options:
Use Customer-Managed Encryption Keys (CMEK)
Use Customer-Supplied Encryption Keys (CSEK)
Create a Key Ring and Key in Cloud KMS
Use Google-Managed Encryption Keys (GMEK)
Encrypt the data locally using a Python script before uploading
50 questions · hints · full answers · grading