Google
PROFESSIONAL-CLOUD-SECURITY-ENGINEER · Question #356
Your organization is storing regulated data in Cloud Storage. Data in Cloud Storage buckets is encrypted by Google-managed encryption keys. To meet compliance requirements, you need to update the…
The correct answer is D. Create a customer-managed encryption key. Change the encryption type in each Cloud Storage. Setting the bucket to use a CMEK and then rewriting (writing) each existing object forces re- encryption under the new customer-managed key; Cloud Storage does not migrate existing objects automatically, so the rewrite is required to update their encryption.
Submitted by certguy· Apr 18, 2026Ensuring data protection
Question
Your organization is storing regulated data in Cloud Storage. Data in Cloud Storage buckets is encrypted by Google-managed encryption keys. To meet compliance requirements, you need to update the existing data to use customer-managed encryption keys instead. What should you do?
Options
- ACreate a new key ring and key in the Cloud Key Management Service. In each Cloud Storage
- BIdentify which projects contain Cloud Storage buckets with regulated data. Apply the
- CCreate a new key ring and key in the Cloud Key Management Service. Identify which projects
- DCreate a customer-managed encryption key. Change the encryption type in each Cloud Storage
How the community answered
(31 responses)- A6% (2)
- B3% (1)
- C16% (5)
- D74% (23)
Explanation
Setting the bucket to use a CMEK and then rewriting (writing) each existing object forces re- encryption under the new customer-managed key; Cloud Storage does not migrate existing objects automatically, so the rewrite is required to update their encryption.
Topics
#Cloud Storage Encryption#Customer-Managed Encryption Keys#Cloud KMS#Data Protection Compliance
Community Discussion
No community discussion yet for this question.