Soru

Zorluk: OrtaManaging Encryption Keys with Cloud KMS

A security operations team is configuring Cloud KMS key management policies for encryption keys protecting Pub/Sub topics. According to corporate compliance rules, the cryptographic keys must automatically rotate every 90 days. Additionally, if an individual key version is suspected of being compromised, security administrators must immediately render that specific version unusable for encryption and decryption operations while preserving the historical KeyRing structure. Which TWO configurations or management actions should the security administrator execute? (Select TWO)

  1. Configure an automated rotation schedule on the CryptoKey specifying a rotation period of 90 days.Cevap
  2. B
    Delete the entire KeyRing resource from the Google Cloud project to immediately destroy all associated key versions.
  3. Change the state of the compromised CryptoKeyVersion to Disabled.Cevap
  4. D
    Grant the primitive Owner role to the Cloud KMS service account to permit administrative key rotation and management.
  5. E
    Remove IAM permissions at the project level to explicitly override and deny access inherited from lower resource levels.

Cevap

The security administrator must set an automated rotation schedule on the CryptoKey with a 90-day period and disable the compromised CryptoKeyVersion.
Automated key rotation is configured by setting a rotation period on the CryptoKey. When a key version is compromised, changing its state to Disabled immediately halts its ability to perform encrypt or decrypt operations without needing to destroy resources or alter KeyRings.

Adım Adım Çözüm

1
Configure key rotation requirements.
Automated 90-day rotation is configured directly on the CryptoKey properties.
Cloud KMS natively supports scheduled automatic creation of new primary key versions based on a defined rotation period.
2
Address key version exposure.
Set the state of the affected CryptoKeyVersion to Disabled.
Disabling a key version prevents cryptographic operations using that version immediately while keeping the resource history intact.

Anahtar Kavram

Cloud KMS Key Lifecycle and Rotation Management
Tahmini Süre:1m 30s
Bu soruyu puanla