nerdexam
Google

PROFESSIONAL-CLOUD-SECURITY-ENGINEER · Question #41

Your company is using Cloud Dataproc for its Spark and Hadoop jobs. You want to be able to create, rotate, and destroy symmetric encryption keys used for the persistent disks used by Cloud Dataproc…

The correct answer is B. Use the Cloud Key Management Service to manage the key encryption key (KEK). The CMEK feature allows you to create, use, and revoke the key encryption key (KEK). Google still controls the data encryption key (DEK). https://cloud.google.com/dataproc/docs/concepts/configuring-clusters/customer-managed-

Submitted by layla.eg· Apr 18, 2026Ensuring data protection

Question

Your company is using Cloud Dataproc for its Spark and Hadoop jobs. You want to be able to create, rotate, and destroy symmetric encryption keys used for the persistent disks used by Cloud Dataproc. Keys can be stored in the cloud. What should you do?

Options

  • AUse the Cloud Key Management Service to manage the data encryption key (DEK).
  • BUse the Cloud Key Management Service to manage the key encryption key (KEK).
  • CUse customer-supplied encryption keys to manage the data encryption key (DEK).
  • DUse customer-supplied encryption keys to manage the key encryption key (KEK).

How the community answered

(25 responses)
  • A
    8% (2)
  • B
    72% (18)
  • C
    16% (4)
  • D
    4% (1)

Explanation

The CMEK feature allows you to create, use, and revoke the key encryption key (KEK). Google still controls the data encryption key (DEK). https://cloud.google.com/dataproc/docs/concepts/configuring-clusters/customer-managed-

Topics

#Cloud KMS#Customer-Managed Encryption Keys (CMEK)#Data encryption#Key management

Community Discussion

No community discussion yet for this question.

Full PROFESSIONAL-CLOUD-SECURITY-ENGINEER Practice