A financial services firm is designing a new application on Google Cloud. The application must store sensitive customer data and comply with regulations that require encryption at rest with keys managed by the company. The company also needs to control key rotation and revocation. Which Google Cloud service should the solutions architect use to meet these requirements?
Cloud KMS with CMEK allows the company to create and manage encryption keys, including rotation and revocation, while Google Cloud services use those keys to encrypt data at rest. This provides the required control over keys for compliance. It is the standard service for managing encryption keys in Google Cloud and integrates with many services like Cloud Storage and BigQuery.
Why this answer
Cloud KMS with customer-managed encryption keys gives the company full control over the lifecycle of encryption keys, including rotation and revocation, while integrating with Google Cloud services to encrypt data at rest. This meets the regulatory requirement for company-managed keys. Other services like IAP or DLP address different aspects of security and do not provide key management.
Exam trap
The trap here is confusing access control or data loss prevention services with encryption key management, when only Cloud KMS with CMEK provides the required control over keys.