Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Google Exam Professional Cloud Security Engineer Topic 3 Question 95 Discussion

Actual exam question for Google's Professional Cloud Security Engineer exam
Question #: 95
Topic #: 3
[All Professional Cloud Security Engineer Questions]

You manage a mission-critical workload for your organization, which is in a highly regulated industry The workload uses Compute Engine VMs to analyze and process the sensitive data after it is uploaded to Cloud Storage from the endpomt computers. Your compliance team has detected that this workload does not meet the data protection requirements for sensitive dat

a. You need to meet these requirements;

* Manage the data encryption key (DEK) outside the Google Cloud boundary.

* Maintain full control of encryption keys through a third-party provider.

* Encrypt the sensitive data before uploading it to Cloud Storage

* Decrypt the sensitive data during processing in the Compute Engine VMs

* Encrypt the sensitive data in memory while in use in the Compute Engine VMs

What should you do?

Choose 2 answers

Show Suggested Answer Hide Answer

Contribute your Thoughts:

Joaquin
7 days ago
Wait, does this mean I can't just use my trusty duct tape and paperclips to secure the data? What is this 'compliance' thing you're talking about?
upvoted 0 times
...
Lisbeth
19 days ago
Yes, and we should encrypt the data in memory while in use in the Compute Engine VMs as well.
upvoted 0 times
...
Elfriede
20 days ago
That makes sense. We also need to decrypt the data during processing in the Compute Engine VMs.
upvoted 0 times
...
Buffy
27 days ago
Option E seems like a solid choice. Maintaining full control over the encryption keys through Customer Managed Encryption Keys is crucial for this highly regulated industry.
upvoted 0 times
...
Carolann
28 days ago
Haha, I'll definitely not be choosing option D. Confidential VMs? That's like putting a giant neon sign that says 'sensitive data inside' on my infrastructure!
upvoted 0 times
Melinda
15 days ago
C) Configure Cloud External Key Manager to encrypt the sensitive data before it is uploaded to Cloud Storage and decrypt the sensitive data after it is downloaded into your VMs
upvoted 0 times
...
Alpha
16 days ago
A) Create a VPC Service Controls service perimeter across your existing Compute Engine VMs and Cloud Storage buckets
upvoted 0 times
...
...
Mirta
1 months ago
I think option C is the way to go. Using Cloud External Key Manager to handle the encryption and decryption of the sensitive data sounds like the best way to meet the compliance requirements.
upvoted 0 times
Daron
2 days ago
So, combining option C with creating a VPC Service Controls service perimeter could be the best approach to ensure data protection and compliance.
upvoted 0 times
...
Charlie
5 days ago
That's true, having a VPC Service Controls service perimeter can add an extra layer of security to protect the sensitive data.
upvoted 0 times
...
Winfred
9 days ago
But wouldn't creating a VPC Service Controls service perimeter also help in meeting the compliance requirements?
upvoted 0 times
...
Gary
25 days ago
I agree, option C seems like the most secure way to handle the encryption and decryption of sensitive data.
upvoted 0 times
...
...
Lisbeth
1 months ago
I think we should encrypt the sensitive data before uploading it to Cloud Storage.
upvoted 0 times
...
Elfriede
2 months ago
I'm not sure what to do about this data protection issue.
upvoted 0 times
...

Save Cancel