Multiple Choice
You need to follow Google-recommended practices to leverage envelope encryption and encrypt data at the application layer. What should you do?
A) Generate a data encryption key (DEK) locally to encrypt the data, and generate a new key encryption key (KEK) in Cloud KMS to encrypt the DEK. Store both the encrypted data and the encrypted DEK.
B) Generate a data encryption key (DEK) locally to encrypt the data, and generate a new key encryption key (KEK) in Cloud KMS to encrypt the DEK. Store both the encrypted data and the KEK.
C) Generate a new data encryption key (DEK) in Cloud KMS to encrypt the data, and generate a key encryption key (KEK) locally to encrypt the key. Store both the encrypted data and the encrypted DEK.
D) Generate a new data encryption key (DEK) in Cloud KMS to encrypt the data, and generate a key encryption key (KEK) locally to encrypt the key. Store both the encrypted data and the KEK.
Correct Answer:

Verified
Correct Answer:
Verified
Q20: A company's application is deployed with a
Q21: A company is deploying their application on
Q22: A customer deployed an application on Compute
Q23: You need to provide a corporate user
Q24: You are creating an internal App Engine
Q26: A customer wants to move their sensitive
Q27: Your team wants to limit users with
Q28: A customer wants to deploy a large
Q29: An employer wants to track how bonus
Q30: A company has redundant mail servers in