An organization wants to configure Customer-Managed Encryption Keys (CMEK) using Cloud KMS to protect sensitive data stored in a Cloud Storage bucket. Which two actions must the security team perform to successfully implement CMEK? (Select TWO.)
- Grant the Cloud KMS CryptoKey Encrypter/Decrypter role to the Cloud Storage service agent account.Cevap
- BAssign the primitive Owner role on the Cloud KMS KeyRing project to the Cloud Storage service agent.
- Configure the Cloud Storage bucket default encryption setting to reference the Cloud KMS key resource identifier.Cevap
- DPass raw 256-bit AES key material in HTTP headers with every object upload request.
Cevap
Granting the Cloud KMS CryptoKey Encrypter/Decrypter role to the Cloud Storage service agent account and setting the Cloud KMS key resource identifier as the default encryption key on the Cloud Storage bucket.
Implementing CMEK for Cloud Storage requires granting the Cloud Storage service agent the specific Cloud KMS CryptoKey Encrypter/Decrypter role and referencing the Cloud KMS key resource ID on the bucket configuration.
Adım Adım Çözüm
Anahtar Kavram
Customer-Managed Encryption Keys (CMEK) setup for Cloud Storage