nerdexam
Google

PROFESSIONAL-CLOUD-SECURITY-ENGINEER · Question #307

You work for a banking organization. You are migrating sensitive customer data to Google Cloud that is currently encrypted at rest while on-premises. There are strict regulatory requirements when…

The correct answer is C. Implement Cloud External Key Manager (Cloud EKM) with Key Access Justifications to integrate. Access Approval : This lets you control access to your organization's data by Google personnel. - Key Access Justifications : This provides a justification for every request to access keys stored in an external key manager.

Submitted by kim_seoul· Apr 18, 2026Ensuring data protection

Question

You work for a banking organization. You are migrating sensitive customer data to Google Cloud that is currently encrypted at rest while on-premises. There are strict regulatory requirements when moving sensitive data to the cloud. Independent of the cloud service provider, you must be able to audit key usage and be able to deny certain types of decrypt requests. You must choose an encryption strategy that will ensure robust security and compliance with the regulations. What should you do?

Options

  • AUtilize Google default encryption and Cloud IAM to keep the keys within your organization's
  • BImplement Cloud External Key Manager (Cloud EKM) with Access Approval, to integrate with
  • CImplement Cloud External Key Manager (Cloud EKM) with Key Access Justifications to integrate
  • DUtilize customer-managed encryption keys (CMEK) created in a dedicated Google Compute

How the community answered

(22 responses)
  • A
    14% (3)
  • B
    18% (4)
  • C
    64% (14)
  • D
    5% (1)

Explanation

  • Access Approval : This lets you control access to your organization's data by Google personnel. - Key Access Justifications : This provides a justification for every request to access keys stored in an external key manager.

Topics

#Cloud EKM#Key Access Justifications#Data Encryption#Regulatory Compliance

Community Discussion

No community discussion yet for this question.

Full PROFESSIONAL-CLOUD-SECURITY-ENGINEER Practice