Soru

Zorluk: OrtaProvisioning Storage and Database Systems

An enterprise organization is setting up a managed relational database infrastructure on Google Cloud for a regional internal application. The system requires full ACID compliance, automated backup capabilities with point-in-time recovery, and compliance with strict data governance mandates requiring customer key management control via Cloud KMS without requiring the operations team to handle raw encryption key material directly. Which database deployment and encryption configuration best fulfills these requirements while avoiding unnecessary cost and operational complexity?

  1. Provision a Cloud SQL for PostgreSQL instance configured with regional High Availability (HA) and encrypted with Customer-Managed Encryption Keys (CMEK) integrated with Cloud KMS.Cevap
  2. B
    Provision a multi-region Cloud Spanner instance configured with Customer-Managed Encryption Keys (CMEK) integrated with Cloud KMS.
  3. C
    Provision a Cloud SQL for PostgreSQL instance configured with regional High Availability (HA) and encrypted with Customer-Supplied Encryption Keys (CSEK).
  4. D
    Provision a standalone Compute Engine instance running PostgreSQL and rely on Storage Transfer Service to execute continuous database backups to a Cloud Storage bucket.

Cevap

Provision a Cloud SQL for PostgreSQL instance configured with regional High Availability (HA) and encrypted with Customer-Managed Encryption Keys (CMEK) integrated with Cloud KMS.
Provisioning a Cloud SQL instance with regional High Availability and Customer-Managed Encryption Keys (CMEK) via Cloud KMS delivers a fully managed ACID-compliant relational database with automated backups and point-in-time recovery. CMEK allows the customer to control key lifecycle policies without the operational burden of storing and supplying raw key material.

Adım Adım Çözüm

1
Evaluate the database workload requirements
Identified the need for a regional, ACID-compliant relational database with point-in-time recovery capabilities.
Cloud SQL fits regional relational database workloads without the high multi-region cost of Cloud Spanner.
2
Determine the encryption and key governance model
Selected Customer-Managed Encryption Keys (CMEK) using Cloud KMS.
CMEK enables organizations to generate, rotate, and manage key encryption keys in Cloud KMS without managing raw secret key files directly.
3
Select the optimal provisioned architecture
Combined regional Cloud SQL HA deployment with Cloud KMS CMEK.
This meets all architectural, recovery, and security compliance constraints efficiently.

Anahtar Kavram

Provisioning Relational Databases and Key Governance
Tahmini Süre:1m 30s
Bu soruyu puanla