nerdexam
Google

PROFESSIONAL-CLOUD-SECURITY-ENGINEER · Question #173

You need to use Cloud External Key Manager to create an encryption key to encrypt specific BigQuery data at rest in Google Cloud. Which steps should you do first?

The correct answer is C. 1. Create or use an existing key with a unique uniform resource identifier (URI) in a supported. https://cloud.google.com/kms/docs/ekm#how_it_works - First, you create or use an existing key in a supported external key management partner system. This key has a unique URI or key path. - Next, you grant your Google Cloud project access to use the key, in the external key…

Submitted by packet_pusher· Apr 18, 2026Ensuring data protection

Question

You need to use Cloud External Key Manager to create an encryption key to encrypt specific BigQuery data at rest in Google Cloud. Which steps should you do first?

Options

  • A
    1. Create or use an existing key with a unique uniform resource identifier (URI) in your Google
  • B
    1. Create or use an existing key with a unique uniform resource identifier (URI) in Cloud Key
  • C
    1. Create or use an existing key with a unique uniform resource identifier (URI) in a supported
  • D
    1. Create an external key with a unique uniform resource identifier (URI) in Cloud Key

How the community answered

(54 responses)
  • A
    2% (1)
  • B
    4% (2)
  • C
    87% (47)
  • D
    7% (4)

Explanation

https://cloud.google.com/kms/docs/ekm#how_it_works - First, you create or use an existing key in a supported external key management partner system. This key has a unique URI or key path. - Next, you grant your Google Cloud project access to use the key, in the external key management partner system. - In your Google Cloud project, you create a Cloud EKM key, using the URI or key path for the externally-managed key.

Topics

#Cloud EKM#Data Encryption#External Key Management#BigQuery Encryption

Community Discussion

No community discussion yet for this question.

Full PROFESSIONAL-CLOUD-SECURITY-ENGINEER Practice