nerdexam
Google

PROFESSIONAL-CLOUD-SECURITY-ENGINEER · Question #193

You are working with a client who plans to migrate their data to Google Cloud. You are responsible for recommending an encryption service to manage their encrypted keys. You have the following…

The correct answer is B. Customer-managed encryption keys with Cloud HSM. https://cloud.google.com/docs/security/key-management-deep-dive https://cloud.google.com/kms/docs/faq "Keys generated with protection level HSM, and the cryptographic operations performed with them, comply with FIPS 140-2 Level 3."

Submitted by olafpl· Apr 18, 2026Ensuring data protection

Question

You are working with a client who plans to migrate their data to Google Cloud. You are responsible for recommending an encryption service to manage their encrypted keys. You have the following requirements: - The master key must be rotated at least once every 45 days. - The solution that stores the master key must be FIPS 140-2 Level 3 validated. - The master key must be stored in multiple regions within the US for redundancy. Which solution meets these requirements?

Options

  • ACustomer-managed encryption keys with Cloud Key Management Service
  • BCustomer-managed encryption keys with Cloud HSM
  • CCustomer-supplied encryption keys
  • DGoogle-managed encryption keys

How the community answered

(31 responses)
  • A
    10% (3)
  • B
    74% (23)
  • C
    13% (4)
  • D
    3% (1)

Explanation

https://cloud.google.com/docs/security/key-management-deep-dive https://cloud.google.com/kms/docs/faq "Keys generated with protection level HSM, and the cryptographic operations performed with them, comply with FIPS 140-2 Level 3."

Topics

#Cloud HSM#Key Management#FIPS 140-2 Level 3#Customer-Managed Encryption Keys

Community Discussion

No community discussion yet for this question.

Full PROFESSIONAL-CLOUD-SECURITY-ENGINEER Practice