Google
PROFESSIONAL-CLOUD-SECURITY-ENGINEER · Question #41
Your company is using Cloud Dataproc for its Spark and Hadoop jobs. You want to be able to create, rotate, and destroy symmetric encryption keys used for the persistent disks used by Cloud Dataproc…
The correct answer is B. Use the Cloud Key Management Service to manage the key encryption key (KEK). The CMEK feature allows you to create, use, and revoke the key encryption key (KEK). Google still controls the data encryption key (DEK). https://cloud.google.com/dataproc/docs/concepts/configuring-clusters/customer-managed-
Submitted by layla.eg· Apr 18, 2026Ensuring data protection
Question
Your company is using Cloud Dataproc for its Spark and Hadoop jobs. You want to be able to create, rotate, and destroy symmetric encryption keys used for the persistent disks used by Cloud Dataproc. Keys can be stored in the cloud. What should you do?
Options
- AUse the Cloud Key Management Service to manage the data encryption key (DEK).
- BUse the Cloud Key Management Service to manage the key encryption key (KEK).
- CUse customer-supplied encryption keys to manage the data encryption key (DEK).
- DUse customer-supplied encryption keys to manage the key encryption key (KEK).
How the community answered
(25 responses)- A8% (2)
- B72% (18)
- C16% (4)
- D4% (1)
Explanation
The CMEK feature allows you to create, use, and revoke the key encryption key (KEK). Google still controls the data encryption key (DEK). https://cloud.google.com/dataproc/docs/concepts/configuring-clusters/customer-managed-
Topics
#Cloud KMS#Customer-Managed Encryption Keys (CMEK)#Data encryption#Key management
Community Discussion
No community discussion yet for this question.