Soru

Zorluk: OrtaData Encryption at Rest, in Transit, and Key Management (KMS/CMEK/CSEK)

Match each data security governance requirement to the appropriate Google Cloud data encryption and key management mechanism.

  • Strict regulatory mandate requiring encryption keys to reside physically in an on-premises Hardware Security Module (HSM) outside of Google Cloud infrastructure while protecting cloud data.Cloud EKM (External Key Manager)
  • Enterprise requirement for customer control over key lifecycles, access policies, and automated rotation schedules directly within GCP using service account IAM roles.Customer-Managed Encryption Keys (CMEK via Cloud KMS)
  • Workload requirement to supply raw AES-256 keys dynamically in API request headers, ensuring keys exist only in transient memory and are never persisted to Google Cloud key storage.Customer-Supplied Encryption Keys (CSEK)
  • Standard operational baseline requiring transparent data encryption at rest across all Google Cloud services without manual key configuration or operational maintenance.Google-default Encryption

Cevap

Cloud EKM corresponds to on-premises key residency mandates; Customer-Managed Encryption Keys (CMEK) corresponds to GCP-managed key control and automated rotation; Customer-Supplied Encryption Keys (CSEK) corresponds to per-request raw key passing without storage; Google-default Encryption corresponds to baseline zero-overhead encryption.
The matching pairs correctly reflect the boundaries of responsibility and control across Google Cloud's data encryption offerings. Cloud EKM satisfies stringent external key control requirements. CMEK balances customer control over key rotation and access policies with native GCP service integration. CSEK ensures raw key material is never stored within GCP key management tools. Google-default Encryption provides invisible, zero-maintenance baseline security for all stored assets.

Adım Adım Çözüm

1
Analyze key storage location requirements.
External key control requiring physical on-premises HSM retention maps directly to Cloud EKM.
Cloud EKM ensures cryptographic keys never leave the external key management infrastructure.
2
Evaluate in-cloud key governance and lifecycle capabilities.
Customer control over keys within GCP using IAM policy bindings and rotation policies maps to CMEK via Cloud KMS.
CMEK allows granular IAM permissioning (Encrypter/Decrypter) and automated rotation inside Google Cloud KMS.
3
Identify key delivery methods for transient processing.
Passing raw AES-256 keys directly within API request headers maps to CSEK.
CSEK guarantees Google does not retain or store key material on disk or within Cloud KMS.
4
Determine default platform security baseline.
Automatic platform-wide encryption without user configuration maps to Google-default Encryption.
Google encrypts all customer data at rest by default using Google-managed service keys.

Anahtar Kavram

Google Cloud Data Encryption Spectrum and Key Management Responsibilities
Tahmini Süre:1m 30s
Bu soruyu puanla