Google
PROFESSIONAL-CLOUD-SECURITY-ENGINEER · Question #181
You are implementing data protection by design and in accordance with GDPR requirements. As part of design reviews, you are told that you need to manage the encryption key for a solution that…
The correct answer is B. Customer-managed encryption keys. https://cloud.google.com/kms/docs/using-other-products#cmek_integrations CMEK is supported for all the listed google services.
Submitted by jordan8· Apr 18, 2026Ensuring data protection
Question
You are implementing data protection by design and in accordance with GDPR requirements. As part of design reviews, you are told that you need to manage the encryption key for a solution that includes workloads for Compute Engine, Google Kubernetes Engine, Cloud Storage, BigQuery, and Pub/Sub. Which option should you choose for this implementation?
Options
- ACloud External Key Manager
- BCustomer-managed encryption keys
- CCustomer-supplied encryption keys
- DGoogle default encryption
How the community answered
(44 responses)- A14% (6)
- B77% (34)
- C2% (1)
- D7% (3)
Explanation
https://cloud.google.com/kms/docs/using-other-products#cmek_integrations CMEK is supported for all the listed google services.
Topics
#Encryption key management#Data at rest encryption#Cloud KMS#GDPR compliance
Community Discussion
No community discussion yet for this question.