nerdexam
Google

PROFESSIONAL-CLOUD-ARCHITECT · Question #242

Your organization has stored sensitive data in a Cloud Storage bucket. For regulatory reasons, your company must be able to rotate the encryption key used to encrypt the data in the bucket. The data w

Sign in or unlock PROFESSIONAL-CLOUD-ARCHITECT to reveal the answer and full explanation for question #242. The question stem and answer options stay visible for context.

Submitted by anjalisingh· Mar 30, 2026Designing for security and compliance

Question

Your organization has stored sensitive data in a Cloud Storage bucket. For regulatory reasons, your company must be able to rotate the encryption key used to encrypt the data in the bucket. The data will be processed in Dataproc. You want to follow Google-recommended practices for security. What should you do?

Options

  • ACreate a key with Cloud Key Management Service (KMS). Encrypt the data using the encrypt
  • BCreate a key with Cloud Key Management Service (KMS). Set the encryption key on the bucket
  • CGenerate a GPG key pair. Encrypt the data using the GPG key. Upload the encrypted data to the
  • DGenerate an AES-256 encryption key. Encrypt the data in the bucket using the customer-supplied

Unlock PROFESSIONAL-CLOUD-ARCHITECT to see the answer

You've previewed enough free PROFESSIONAL-CLOUD-ARCHITECT questions. Unlock PROFESSIONAL-CLOUD-ARCHITECT for full answers, explanations, the timed quiz mode, progress tracking, and the master PDF. Question stem and options stay visible so you can still see what's on the exam.

Topics

#CMEK#key rotation#Cloud KMS#Cloud Storage encryption
Full PROFESSIONAL-CLOUD-ARCHITECT Practice