Cyber Monday 2024! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Google Exam Professional Cloud Security Engineer Topic 2 Question 77 Discussion

Actual exam question for Google's Professional Cloud Security Engineer exam
Question #: 77
Topic #: 2
[All Professional Cloud Security Engineer Questions]

You manage a mission-critical workload for your organization, which is in a highly regulated industry The workload uses Compute Engine VMs to analyze and process the sensitive data after it is uploaded to Cloud Storage from the endpomt computers. Your compliance team has detected that this workload does not meet the data protection requirements for sensitive dat

a. You need to meet these requirements;

* Manage the data encryption key (DEK) outside the Google Cloud boundary.

* Maintain full control of encryption keys through a third-party provider.

* Encrypt the sensitive data before uploading it to Cloud Storage

* Decrypt the sensitive data during processing in the Compute Engine VMs

* Encrypt the sensitive data in memory while in use in the Compute Engine VMs

What should you do?

Choose 2 answers

Show Suggested Answer Hide Answer

Contribute your Thoughts:

Beth
6 months ago
Alright, C and E it is then. Makes sense for compliance and key management.
upvoted 0 times
...
Truman
6 months ago
B and D don't seem to address encryption keys managed outside Google Cloud, so I'm ruling them out.
upvoted 0 times
...
Jani
6 months ago
Agreed. C and E fit the requirements of using an external key manager and encrypting data before upload.
upvoted 0 times
...
Rebbeca
6 months ago
I'm leaning towards options C and E. They both involve managing encryption keys.
upvoted 0 times
...
Melodie
7 months ago
Definitely, lots of things to consider here.
upvoted 0 times
...
Beth
7 months ago
This question seems tough, don't you think?
upvoted 0 times
...

Save Cancel