Google
PROFESSIONAL-CLOUD-SECURITY-ENGINEER · Question #40
A customer wants to move their sensitive workloads to a Compute Engine-based cluster using Managed Instance Groups (MIGs). The jobs are bursty and must be completed quickly. They have a requirement…
The correct answer is B. Customer-managed encryption keys (CMEK) using Cloud Key Management Service (KMS). Customer Managed Encryption keys using KMS lets users control the key management and rotation policies and Compute Engine Disks support CMEKs. https://cloud.google.com/kubernetes-engine/docs/how-to/dynamic-provisioning-cmek
Submitted by alyssa_d· Apr 18, 2026Ensuring data protection
Question
A customer wants to move their sensitive workloads to a Compute Engine-based cluster using Managed Instance Groups (MIGs). The jobs are bursty and must be completed quickly. They have a requirement to be able to manage and rotate the encryption keys. Which boot disk encryption solution should you use on the cluster to meet this customer's requirements?
Options
- ACustomer-supplied encryption keys (CSEK)
- BCustomer-managed encryption keys (CMEK) using Cloud Key Management Service (KMS)
- CEncryption by default
- DPre-encrypting files before transferring to Google Cloud Platform (GCP) for analysis
How the community answered
(66 responses)- A3% (2)
- B83% (55)
- C5% (3)
- D9% (6)
Explanation
Customer Managed Encryption keys using KMS lets users control the key management and rotation policies and Compute Engine Disks support CMEKs. https://cloud.google.com/kubernetes-engine/docs/how-to/dynamic-provisioning-cmek
Topics
#Encryption#Cloud KMS#Compute Engine#Key Management
Community Discussion
No community discussion yet for this question.