Examtopics

Professional Cloud Developer
  • Topic 1 Question 173

    Your company has a new security initiative that requires all data stored in Google Cloud to be encrypted by customer-managed encryption keys. You plan to use Cloud Key Management Service (KMS) to configure access to the keys. You need to follow the "separation of duties" principle and Google-recommended best practices. What should you do?

    2 つ選択
    • Provision Cloud KMS in its own project.

    • Do not assign an owner to the Cloud KMS project.

    • Provision Cloud KMS in the project where the keys are being used.

    • Grant the roles/cloudkms.admin role to the owner of the project where the keys from Cloud KMS are being used.

    • Grant an owner role for the Cloud KMS project to a different user than the owner of the project where the keys from Cloud KMS are being used.


    シャッフルモード