A financial services company is designing a multi-tier application on Google Cloud. The application must meet PCI DSS compliance, with data encrypted at rest and in transit. They plan to use Cloud SQL for PostgreSQL for transactional data and Cloud Storage for archival data. Which TWO actions should the architect take to meet compliance requirements?
Trap 1: Configure client-side encryption in the application code
Client-side encryption is not a recommended architecture pattern for Cloud SQL and would add complexity.
Trap 2: Rely on Google-managed default encryption for all data
Default encryption does not meet PCI DSS requirements for key management control.
Trap 3: Use Cloud HSM with a key generated outside of Google Cloud
Cloud HSM is a key management service, but the question asks for actions specifically for encryption at rest and in transit; CMEK already covers this.
- A
Configure client-side encryption in the application code
Why it fails: Client-side encryption is not a recommended architecture pattern for Cloud SQL and would add complexity.
- B
Rely on Google-managed default encryption for all data
Why it fails: Default encryption does not meet PCI DSS requirements for key management control.
- C
Enable customer-managed encryption keys (CMEK) on Cloud SQL and Cloud Storage
CMEK satisfies PCI DSS encryption-at-rest requirements by giving the organisation control over the keys protecting Cloud SQL and Cloud Storage data. Customer-managed keys in Cloud KMS let the architect rotate, revoke, and audit key usage, meeting the compliance mandate for controlled cryptographic key management.
- D
Use VPC Service Controls to restrict data access
VPC Service Controls build a service perimeter around Cloud SQL and Cloud Storage APIs, preventing data exfiltration and unauthorised access across project boundaries. This enforces the network-level isolation PCI DSS expects for cardholder data environments, complementing encryption with access-boundary controls.
- E
Use Cloud HSM with a key generated outside of Google Cloud
Why it fails: Cloud HSM is a key management service, but the question asks for actions specifically for encryption at rest and in transit; CMEK already covers this.