Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Google Exam Professional-Cloud-Security-Engineer Topic 3 Question 70 Discussion

Actual exam question for Google's Professional Cloud Security Engineer exam
Question #: 70
Topic #: 3
[All Professional Cloud Security Engineer Questions]

You manage a mission-critical workload for your organization, which is in a highly regulated industry The workload uses Compute Engine VMs to analyze and process the sensitive data after it is uploaded to Cloud Storage from the endpomt computers. Your compliance team has detected that this workload does not meet the data protection requirements for sensitive dat

a. You need to meet these requirements;

* Manage the data encryption key (DEK) outside the Google Cloud boundary.

* Maintain full control of encryption keys through a third-party provider.

* Encrypt the sensitive data before uploading it to Cloud Storage

* Decrypt the sensitive data during processing in the Compute Engine VMs

* Encrypt the sensitive data in memory while in use in the Compute Engine VMs

What should you do?

Choose 2 answers

Show Suggested Answer Hide Answer

Contribute your Thoughts:

Celestina
6 months ago
Agreed, those two options seem the most comprehensive. The Confidential VMs in options B and D are a bit overkill, in my opinion.
upvoted 0 times
...
Berry
6 months ago
Hmm, I'm thinking options C and E are the way to go. Configuring Cloud External Key Manager and Customer Managed Encryption Keys seem like the best way to meet all the requirements.
upvoted 0 times
...
Dorathy
6 months ago
Exactly. I wouldn't want to be the one who has to explain to the compliance team why we didn't do that. That's a conversation I'd rather avoid.
upvoted 0 times
William
5 months ago
By following these steps, we can ensure that the sensitive data is properly encrypted and protected at all times.
upvoted 0 times
...
Page
6 months ago
B) Migrate the Compute Engine VMs to Confidential VMs to access the sensitive data.
upvoted 0 times
...
Glenna
6 months ago
I agree, it's crucial to meet the data protection requirements for sensitive data.
upvoted 0 times
...
Arleen
6 months ago
E) Configure Customer Managed Encryption Keys to encrypt the sensitive data before it is uploaded to Cloud Storage, and decrypt the sensitive data after it is downloaded into your VMs.
upvoted 0 times
...
Ligia
6 months ago
A) Create a VPC Service Controls service perimeter across your existing Compute Engine VMs and Cloud Storage buckets
upvoted 0 times
...
...
Roosevelt
6 months ago
Haha, yeah, Confidential VMs are like the fancy sports car of VMs - you really only need them if you're trying to impress someone.
upvoted 0 times
...

Save Cancel
az-700  pass4success  az-104  200-301  200-201  cissp  350-401  350-201  350-501  350-601  350-801  350-901  az-720  az-305  pl-300  

Warning: Cannot modify header information - headers already sent by (output started at /pass.php:70) in /pass.php on line 77