Google
PROFESSIONAL-CLOUD-SECURITY-ENGINEER · Question #10
Your company is storing sensitive data in Cloud Storage. You want a key generated on-premises to be used in the encryption process. What should you do?
The correct answer is C. Use customer-supplied encryption keys to manage the data encryption key (DEK). This is a Customer-supplied encryption keys (CSEK). We generate our own encryption key and manage it on-premises. A KEK never leaves Cloud KMS.There is no KEK or KMS on-premises. Encryption at rest by default, with various key management options…
Submitted by certguy· Apr 18, 2026Ensuring data protection
Question
Your company is storing sensitive data in Cloud Storage. You want a key generated on-premises to be used in the encryption process. What should you do?
Options
- AUse the Cloud Key Management Service to manage a data encryption key (DEK).
- BUse the Cloud Key Management Service to manage a key encryption key (KEK).
- CUse customer-supplied encryption keys to manage the data encryption key (DEK).
- DUse customer-supplied encryption keys to manage the key encryption key (KEK).
How the community answered
(20 responses)- A5% (1)
- B5% (1)
- C90% (18)
Explanation
This is a Customer-supplied encryption keys (CSEK). We generate our own encryption key and manage it on-premises. A KEK never leaves Cloud KMS.There is no KEK or KMS on-premises. Encryption at rest by default, with various key management options. https://cloud.google.com/security/encryption-at-rest
Topics
#Cloud Storage#Encryption#Customer-Supplied Encryption Keys (CSEK)#Key Management
Community Discussion
No community discussion yet for this question.