
Google CloudProfessional Cloud Security Engineer
Domain 3Objective 2
3.2 Managing Encryption at Rest, in Transit, and in Use PROFESSIONAL-CLOUD-SECURITY-ENGINEER Practice Questions (Page 5)
Part of the Ensuring data protection domain, which accounts for 23% of the PROFESSIONAL-CLOUD-SECURITY-ENGINEER exam.
36questions here
8free pages
12concepts
23%of the exam
Questions 21–25
- 21
A company stores sensitive customer data in Cloud Storage and must be able to revoke access by deleting encryption keys. Which encryption method should they apply to the Cloud Storage bucket?
Select an answer first - 22
A startup is storing non-sensitive marketing brochures in Cloud Storage and serving them to the public via a website. They have no regulatory requirements for key control. Which statement about Google's default encryption is correct?
Select an answer first - 23
A company is designing a data-encryption strategy for two workloads. Workload A stores non-sensitive marketing data and has no compliance requirements. Workload B stores payment card data and is subject to a standard that requires keys to be protected by a FIPS 140-2 Level 3 certified HSM. The company wants to minimize cost and operational overhead. What should the security team recommend?
Select an answer first - 24
A customer wants to use encryption keys that are software-based and managed in Cloud KMS. Which encryption option should they choose?
Select an answer first - 25
A company wants to use CMEK for a new application but has a corporate requirement to use keys generated by its own key-management system. The company has exported the key in a standard format and wants to import it into Cloud KMS. What must the security team do to ensure the key can be imported securely?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Google Cloud. “PROFESSIONAL-CLOUD-SECURITY-ENGINEER” is a trademark of its owner, used for identification only.