nerdexam
Google

PROFESSIONAL-CLOUD-SECURITY-ENGINEER · Question #356

Your organization is storing regulated data in Cloud Storage. Data in Cloud Storage buckets is encrypted by Google-managed encryption keys. To meet compliance requirements, you need to update the…

The correct answer is D. Create a customer-managed encryption key. Change the encryption type in each Cloud Storage. Setting the bucket to use a CMEK and then rewriting (writing) each existing object forces re- encryption under the new customer-managed key; Cloud Storage does not migrate existing objects automatically, so the rewrite is required to update their encryption.

Submitted by certguy· Apr 18, 2026Ensuring data protection

Question

Your organization is storing regulated data in Cloud Storage. Data in Cloud Storage buckets is encrypted by Google-managed encryption keys. To meet compliance requirements, you need to update the existing data to use customer-managed encryption keys instead. What should you do?

Options

  • ACreate a new key ring and key in the Cloud Key Management Service. In each Cloud Storage
  • BIdentify which projects contain Cloud Storage buckets with regulated data. Apply the
  • CCreate a new key ring and key in the Cloud Key Management Service. Identify which projects
  • DCreate a customer-managed encryption key. Change the encryption type in each Cloud Storage

How the community answered

(31 responses)
  • A
    6% (2)
  • B
    3% (1)
  • C
    16% (5)
  • D
    74% (23)

Explanation

Setting the bucket to use a CMEK and then rewriting (writing) each existing object forces re- encryption under the new customer-managed key; Cloud Storage does not migrate existing objects automatically, so the rewrite is required to update their encryption.

Topics

#Cloud Storage Encryption#Customer-Managed Encryption Keys#Cloud KMS#Data Protection Compliance

Community Discussion

No community discussion yet for this question.

Full PROFESSIONAL-CLOUD-SECURITY-ENGINEER Practice