A large financial institution is moving its Big Data analytics to Google Cloud Platform. They want to have maximum control over the encryption process of data stored at rest in BigQuery.
What technique should the institution use?
A . Use Cloud Storage as a federated Data Source.
B . Use a Cloud Hardware Security Module (Cloud HSM).
C . Customer-managed encryption keys (CMEK).
D . Customer-supplied encryption keys (CSEK).
Answer: C
Explanation:
If you want to manage the key encryption keys used for your data at rest, instead of having Google manage the keys, use Cloud Key Management Service to manage your keys. This scenario is known as customer-managed encryption keys (CMEK). https://cloud.google.com/bigquery/docs/encryption-at-rest
Reference: https://cloud.google.com/bigquery/docs/encryption-at-rest
Latest Professional Cloud Security Engineer Dumps Valid Version with 93 Q&As
Latest And Valid Q&A | Instant Download | Once Fail, Full Refund