nerdexam
Google

PROFESSIONAL-CLOUD-SECURITY-ENGINEER · Question #10

Your company is storing sensitive data in Cloud Storage. You want a key generated on-premises to be used in the encryption process. What should you do?

The correct answer is C. Use customer-supplied encryption keys to manage the data encryption key (DEK). This is a Customer-supplied encryption keys (CSEK). We generate our own encryption key and manage it on-premises. A KEK never leaves Cloud KMS.There is no KEK or KMS on-premises. Encryption at rest by default, with various key management options…

Submitted by certguy· Apr 18, 2026Ensuring data protection

Question

Your company is storing sensitive data in Cloud Storage. You want a key generated on-premises to be used in the encryption process. What should you do?

Options

  • AUse the Cloud Key Management Service to manage a data encryption key (DEK).
  • BUse the Cloud Key Management Service to manage a key encryption key (KEK).
  • CUse customer-supplied encryption keys to manage the data encryption key (DEK).
  • DUse customer-supplied encryption keys to manage the key encryption key (KEK).

How the community answered

(20 responses)
  • A
    5% (1)
  • B
    5% (1)
  • C
    90% (18)

Explanation

This is a Customer-supplied encryption keys (CSEK). We generate our own encryption key and manage it on-premises. A KEK never leaves Cloud KMS.There is no KEK or KMS on-premises. Encryption at rest by default, with various key management options. https://cloud.google.com/security/encryption-at-rest

Topics

#Cloud Storage#Encryption#Customer-Supplied Encryption Keys (CSEK)#Key Management

Community Discussion

No community discussion yet for this question.

Full PROFESSIONAL-CLOUD-SECURITY-ENGINEER Practice