Question 66 of 318
Single answerYou want data on Compute Engine disks to be encrypted at rest with keys managed by Cloud Key Management Service (KMS). Cloud Identity and Access
Management (IAM) permissions to these keys must be managed in a grouped way because the permissions should be the same for all keys.
What should you do?
What should you do?
ACreate a single KeyRing for all persistent disks and all Keys in this KeyRing. Manage the IAM permissions at the Key level.
✓BCreate a single KeyRing for all persistent disks and all Keys in this KeyRing. Manage the IAM permissions at the KeyRing level.
CCreate a KeyRing per persistent disk, with each KeyRing containing a single Key. Manage the IAM permissions at the Key level.
DCreate a KeyRing per persistent disk, with each KeyRing containing a single Key. Manage the IAM permissions at the KeyRing level.
✓
Correct Answer: B
Create a single KeyRing for all persistent disks and all Keys in this KeyRing. Manage the IAM permissions at the KeyRing level.
▥
Explanation
The correct answer is highlighted above. Review the wording carefully, then use the next question to continue building your understanding of Google certification topics.