Valid Professional-Cloud-Security-Engineer Dumps shared by ExamDiscuss.com for Helping Passing Professional-Cloud-Security-Engineer Exam! ExamDiscuss.com now offer the newest Professional-Cloud-Security-Engineer exam dumps, the ExamDiscuss.com Professional-Cloud-Security-Engineer exam questions have been updated and answers have been corrected get the newest ExamDiscuss.com Professional-Cloud-Security-Engineer dumps with Test Engine here:
You are working with a client who plans to migrate their data to Google Cloud. You are responsible for recommending an encryption service to manage their encrypted keys. You have the following requirements: * The master key must be rotated at least once every 45 days. * The solution that stores the master key must be FIPS 140-2 Level 3 validated. * The master key must be stored in multiple regions within the US for redundancy. Which solution meets these requirements?
Correct Answer: B
To meet the requirements of rotating the master key every 45 days, achieving FIPS 140-2 Level 3 validation, and ensuring the master key is stored redundantly in multiple US regions, you should use Customer-managed encryption keys with Cloud HSM. Here's how: * Set Up Cloud HSM: * Deploy Cloud HSM in your Google Cloud environment. Cloud HSM provides a hardware-based key management solution that meets FIPS 140-2 Level 3 compliance. * Create and Manage Keys: * Create your encryption keys in Cloud HSM. These keys can be managed and rotated per your policy requirements. * Key Rotation: * Set up a key rotation schedule to rotate the master key every 45 days. Cloud HSM allows you to automate this process. * Geographic Redundancy: * Ensure that your Cloud HSM configuration spans multiple regions within the US to achieve redundancy. This will ensure that your keys are available even if a particular region experiences an outage. * Compliance: * Cloud HSM's FIPS 140-2 Level 3 validation ensures that your encryption keys are managed in a secure and compliant manner. Benefits: * Security and Compliance: Meets stringent compliance requirements. * Automated Management: Simplifies key management and rotation. * Redundancy: Ensures high availability of keys across multiple regions. References * Cloud HSM Documentation * Key Management with Cloud KMS and Cloud HSM