A large financial institution is moving its Big Data analytics to Google Cloud Platform. They want to have maximum control over the encryption process of data stored at rest in BigQuery. What technique should the institution use?
A.
Use Cloud Storage as a federated Data Source.
B.
Use a Cloud Hardware Security Module (Cloud HSM).
CSEK is only supported in Google Cloud Storage and Compute Engine, therefore D cannot be the right answer.
Ideally, it would be client-side encryption, with BigQuery providing another round of encryption of the encrypted data - https://cloud.google.com/bigquery/docs/encryption-at-rest#client_side_encryption, but since that is not one of the options, we can go with C as the next best option.
Correct answer is D
D. Customer-supplied encryption keys (CSEK).
Here's an explanation of why CSEK is the best choice and a brief review of the other options:
Customer-supplied encryption keys (CSEK): CSEK allows the institution to manage their own encryption keys and supply these keys to Google Cloud Platform when needed. This provides maximum control over the encryption process because the institution retains possession of the encryption keys and can rotate, revoke, or replace them as desired.
C is the RIGHT ONE!!!
If you want to manage the key encryption keys used for your data at rest, instead of having Google manage the keys, use Cloud Key Management Service to manage your keys. This scenario is known as customer-managed encryption keys (CMEK).
https://cloud.google.com/bigquery/docs/encryption-at-rest
For maximum control surely D is the correct answer.
CSEK:
https://cloud.google.com/security/encryption-at-rest/customer-supplied-encryption-keys
CMEK
https://cloud.google.com/bigquery/docs/encryption-at-rest
upvoted 2 times
...
Log in to ExamTopics
Sign in:
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.
Upvoting a comment with a selected answer will also increase the vote count towards that answer by one.
So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.
Ganshank
Highly Voted 4 years, 6 months agosmart123
4 years, 5 months agoSQLbox
Most Recent 2 months, 2 weeks agocrazycosmos
3 months, 3 weeks agoSQLbox
4 months agoIshu_awsguy
1 year, 5 months agoIshu_awsguy
1 year, 5 months agoAwesomeGCP
2 years, 1 month agoDebasishLowes
3 years, 8 months agoAniyadu
3 years, 10 months ago[Removed]
4 years agosaurabh1805
4 years, 1 month agoMohitA
4 years, 3 months agoaiwaai
4 years, 3 months agoArizonaClassics
4 years, 3 months agoArizonaClassics
4 years, 3 months agoranjeetpatil
4 years, 5 months agosrinidutt
4 years, 6 months agoxhova
4 years, 7 months agojonclem
4 years, 8 months ago