Soru

Zorluk: KolayData Encryption at Rest, in Transit, and Key Management (KMS/CMEK/CSEK)

An organization wants to configure Customer-Managed Encryption Keys (CMEK) using Cloud KMS to protect sensitive data stored in a Cloud Storage bucket. Which two actions must the security team perform to successfully implement CMEK? (Select TWO.)

  1. Grant the Cloud KMS CryptoKey Encrypter/Decrypter role to the Cloud Storage service agent account.Cevap
  2. B
    Assign the primitive Owner role on the Cloud KMS KeyRing project to the Cloud Storage service agent.
  3. Configure the Cloud Storage bucket default encryption setting to reference the Cloud KMS key resource identifier.Cevap
  4. D
    Pass raw 256-bit AES key material in HTTP headers with every object upload request.

Cevap

Granting the Cloud KMS CryptoKey Encrypter/Decrypter role to the Cloud Storage service agent account and setting the Cloud KMS key resource identifier as the default encryption key on the Cloud Storage bucket.
Implementing CMEK for Cloud Storage requires granting the Cloud Storage service agent the specific Cloud KMS CryptoKey Encrypter/Decrypter role and referencing the Cloud KMS key resource ID on the bucket configuration.

Adım Adım Çözüm

1
Identify key management permissions required by Cloud Storage for CMEK integration.
The Cloud Storage service agent requires the Cloud KMS CryptoKey Encrypter/Decrypter role on the Cloud KMS key.
Google Cloud service agents use service-specific service accounts to execute operations like key encryption and decryption on behalf of users.
2
Apply the key reference configuration to the target Cloud Storage bucket.
The bucket default encryption configuration points to the Cloud KMS key resource name.
This guarantees all newly uploaded objects are encrypted with the specified CMEK key.

Anahtar Kavram

Customer-Managed Encryption Keys (CMEK) setup for Cloud Storage
Bu soruyu puanla