Question 98 of 318
Single answerYou need to implement an encryption at-rest strategy that reduces key management complexity for non-sensitive data and protects sensitive data while providing the flexibility of controlling the key residency and rotation schedule. FIPS 140-2 L1 compliance is required for all data types.
What should you do?
What should you do?
AEncrypt non-sensitive data and sensitive data with Cloud External Key Manager.
BEncrypt non-sensitive data and sensitive data with Cloud Key Management Service
CEncrypt non-sensitive data with Google default encryption, and encrypt sensitive data with Cloud External Key Manager.
✓DEncrypt non-sensitive data with Google default encryption, and encrypt sensitive data with Cloud Key Management Service.
✓
Correct Answer: D
Encrypt non-sensitive data with Google default encryption, and encrypt sensitive data with Cloud Key Management Service.
▥
Explanation
The correct answer is highlighted above. Review the wording carefully, then use the next question to continue building your understanding of Google certification topics.