nerdexam
Google

PROFESSIONAL-CLOUD-SECURITY-ENGINEER · Question #40

A customer wants to move their sensitive workloads to a Compute Engine-based cluster using Managed Instance Groups (MIGs). The jobs are bursty and must be completed quickly. They have a requirement…

The correct answer is B. Customer-managed encryption keys (CMEK) using Cloud Key Management Service (KMS). Customer Managed Encryption keys using KMS lets users control the key management and rotation policies and Compute Engine Disks support CMEKs. https://cloud.google.com/kubernetes-engine/docs/how-to/dynamic-provisioning-cmek

Submitted by alyssa_d· Apr 18, 2026Ensuring data protection

Question

A customer wants to move their sensitive workloads to a Compute Engine-based cluster using Managed Instance Groups (MIGs). The jobs are bursty and must be completed quickly. They have a requirement to be able to manage and rotate the encryption keys. Which boot disk encryption solution should you use on the cluster to meet this customer's requirements?

Options

  • ACustomer-supplied encryption keys (CSEK)
  • BCustomer-managed encryption keys (CMEK) using Cloud Key Management Service (KMS)
  • CEncryption by default
  • DPre-encrypting files before transferring to Google Cloud Platform (GCP) for analysis

How the community answered

(66 responses)
  • A
    3% (2)
  • B
    83% (55)
  • C
    5% (3)
  • D
    9% (6)

Explanation

Customer Managed Encryption keys using KMS lets users control the key management and rotation policies and Compute Engine Disks support CMEKs. https://cloud.google.com/kubernetes-engine/docs/how-to/dynamic-provisioning-cmek

Topics

#Encryption#Cloud KMS#Compute Engine#Key Management

Community Discussion

No community discussion yet for this question.

Full PROFESSIONAL-CLOUD-SECURITY-ENGINEER Practice