Welcome to ExamTopics
ExamTopics Logo
- Expert Verified, Online, Free.
exam questions

Exam Professional Cloud Security Engineer All Questions

View all questions & answers for the Professional Cloud Security Engineer exam

Exam Professional Cloud Security Engineer topic 1 question 273 discussion

Actual exam question from Google's Professional Cloud Security Engineer
Question #: 273
Topic #: 1
[All Professional Cloud Security Engineer Questions]

You are working with developers to secure custom training jobs running on Vertex AI. For compliance reasons, all supported data types must be encrypted by key materials that reside in the Europe region and are controlled by your organization. The encryption activity must not impact the training operation in Vertex AI. What should you do?

  • A. Encrypt the code, training data, and metadata with Google default encryption. Use customer-managed encryption keys (CMEK) for the trained models exported to Cloud Storage buckets.
  • B. Encrypt the code, training data, metadata, and exported trained models with customer-managed encryption keys (CMEK).
  • C. Encrypt the code, training data, and exported trained models with customer-managed encryption keys (CMEK).
  • D. Encrypt the code, training data, and metadata with Google default encryption. Implement an organization policy that enforces a constraint to restrict the Cloud KMS location to the Europe region.
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
3fd692e
1 week, 5 days ago
Selected Answer: B
B is correct. D looks good but uses Google Managed Encryption Keys which violates the requirement of control the encryption resources outlined in the question.
upvoted 1 times
...
BondleB
2 weeks, 3 days ago
Selected Answer: D
Option D enforces that all supported data types must be encrypted by key materials that reside in the Europe region.
upvoted 2 times
...
dat987
1 month, 1 week ago
Answer is C The CMEK key doesn't encrypt metadata, like the instance's name and region, associated with your Vertex AI Workbench instance. Metadata associated with Vertex AI Workbench instances is always encrypted using Google's default encryption mechanism.
upvoted 1 times
...
yokoyan
2 months, 2 weeks ago
Selected Answer: B
I think it's B.
upvoted 1 times
BondleB
2 weeks, 3 days ago
In general, the CMEK key does not encrypt metadata associated with your operation, like the job's name and region, or a dataset's display name. Metadata associated with operations is always encrypted using Google's default encryption mechanism.
upvoted 1 times
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...