Topic 1 Question 45
A large financial institution is moving its Big Data analytics to Google Cloud Platform. They want to have maximum control over the encryption process of data stored at rest in BigQuery. What technique should the institution use?
Use Cloud Storage as a federated Data Source.
Use a Cloud Hardware Security Module (Cloud HSM).
Customer-managed encryption keys (CMEK).
Customer-supplied encryption keys (CSEK).
ユーザの投票
コメント(14)
CSEK is only supported in Google Cloud Storage and Compute Engine, therefore D cannot be the right answer. Ideally, it would be client-side encryption, with BigQuery providing another round of encryption of the encrypted data - https://cloud.google.com/bigquery/docs/encryption-at-rest#client_side_encryption, but since that is not one of the options, we can go with C as the next best option.
👍 15Ganshank2020/05/23Ans is C. BigQuery does not support CSEK. https://cloud.google.com/security/encryption-at-rest. https://cloud.google.com/security/encryption-at-rest
👍 4ranjeetpatil2020/06/11Answer is D. For max control you don't want to store the Key with Google.
👍 3xhova2020/04/03
シャッフルモード