What should you do?

You want data on Compute Engine disks to be encrypted at rest with keys managed by Cloud Key Management Service (KMS). Cloud Identity and Access Management (IAM) permissions to these keys must be managed in a grouped way because the permissions should be the same for all keys.

What should you do?
A . Create a single KeyRing for all persistent disks and all Keys in this KeyRing. Manage the IAM permissions at the Key level.
B . Create a single KeyRing for all persistent disks and all Keys in this KeyRing. Manage the IAM permissions at the KeyRing level.
C . Create a KeyRing per persistent disk, with each KeyRing containing a single Key.
Manage the IAM permissions at the Key level.
D . Create a KeyRing per persistent disk, with each KeyRing containing a single Key.
Manage the IAM permissions at the KeyRing level.

Answer: B

Explanation:

https://cloud.netapp.com/blog/gcp-cvo-blg-how-to-use-google-cloud-encryption-with-a-persistent-disk

Subscribe
Notify of
guest
0 Comments
Inline Feedbacks
View all comments