Skip to content

Deciding who should hold the encryption keys

Google Cloud encrypts data at rest by default, but customers can choose who controls the encryption keys based on compliance and operational needs. Google-managed keys require no setup, CMEK gives control via Cloud KMS while Google still handles the cryptographic operations, and CSEK lets customers supply and manage their own keys entirely outside Google.

Must-know

  • GMEK (Google-managed encryption keys) is the default for services like BigQuery, Cloud Storage, and Compute Engine, with no configuration required and keys fully managed and rotated by Google.
  • CMEK (customer-managed encryption keys) lets you create and control key lifecycle (rotation, disabling, destruction) in Cloud KMS while Google still performs encryption/decryption operations, giving an audit trail via Cloud Audit Logs without exposing the raw key.
  • CMEK is the right choice when compliance or governance requires demonstrable control over key rotation/revocation and the ability to disable access to data by disabling the key, and is supported by services like BigQuery, Cloud Storage, and Compute Engine.
  • CSEK (customer-supplied encryption keys) requires the customer to generate and provide the AES-256 key on each API call; Google uses it transiently for the operation and does not store it, so losing the key means permanent data loss.
  • CSEK has narrower support (mainly Compute Engine persistent disks and Cloud Storage) and is chosen only when an organization must retain the raw key material entirely outside Google's infrastructure.
  • Destroying a CMEK key in Cloud KMS renders all data encrypted with it permanently unreadable, making key management (not just data deletion) a critical part of data lifecycle and compliance planning.
Check this objectiveFree · always available

A healthcare analytics team stores patient records in BigQuery. Company policy requires that the security team be able to immediately revoke access to all data in a dataset by disabling a single key, view key usage in Cloud Audit Logs, and set a key rotation schedule, but the team does not want to manage or transmit raw key material. Which encryption option satisfies these requirements?

Your objective map0 tried · 0 right · 41 untouched

What you have tried across GCP ADP's objectives, not a readiness score.

Coverage checked against the published exam guide on Aug 12, 2026.

These are independent practice questions, written against this certification's published exam guide. They are not the certification vendor's own questions, and not the real exam.