
Google CloudProfessional Cloud Security Engineer
Domain 3Objective 2
3.2 Managing Encryption at Rest, in Transit, and in Use PROFESSIONAL-CLOUD-SECURITY-ENGINEER Practice Questions (Page 2)
Part of the Ensuring data protection domain, which accounts for 23% of the PROFESSIONAL-CLOUD-SECURITY-ENGINEER exam.
36questions here
8free pages
12concepts
23%of the exam
Questions 6–10
- 6
A company runs a batch data-processing job on Dataflow that handles personally identifiable information (PII). The security team wants to protect the data while it is being processed, in addition to protecting it at rest and in transit. The team has confirmed that the Dataflow workers run on Compute Engine. What should the security team do?
Select an answer first - 7
A customer wants to use encryption keys managed by an external partner for their BigQuery data. Which encryption method should they apply?
Select an answer first - 8
A multinational company uses Cloud EKM to encrypt data in BigQuery with keys stored in an on-premises HSM. The company has a disaster-recovery (DR) site in a different region that also has an HSM. The security team wants to ensure that if the primary HSM becomes unavailable, BigQuery can still decrypt data using the DR HSM. What should the security team do?
Select an answer first - 9
A customer wants to rotate a CMEK key that is used to encrypt data in BigQuery. Where should the rotation be configured?
Select an answer first - 10
When using Cloud EKM, where are the encryption keys stored?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Google Cloud. “PROFESSIONAL-CLOUD-SECURITY-ENGINEER” is a trademark of its owner, used for identification only.