Official Google Cloud Certified Professional Cloud Security Engineer Exam Guide by Ankush Chowdhary and Prashant Kulkarni

Official Google Cloud Certified Professional Cloud Security Engineer Exam Guide by Ankush Chowdhary and Prashant Kulkarni

Author:Ankush Chowdhary and Prashant Kulkarni
Language: eng
Format: epub
Publisher: Packt Publishing Pvt. Ltd.
Published: 2023-07-28T00:00:00+00:00


Note

The rotation of the CMEK will not impact data availability since the service keeps track of which CMEK version was used to encrypt the data and will use that version to decrypt it.

CMEK compliance

Some services do not directly store data, or store data for only a brief period as an intermediate step in a long-running operation. For this type of workload, it is not practical to encrypt each write separately. These services do not offer CMEK integrations but can offer CMEK compliance, often with no configuration on your part.

A CMEK-compliant service encrypts temporary data by using an ephemeral key that only exists in memory and is never written to disk. When the temporary data is no longer needed, the ephemeral key is flushed from memory, and the encrypted data cannot be accessed, even if the storage resource still exists.

A CMEK-compliant service might offer the ability to send its output to a service with a CMEK integration, such as Cloud Storage.



Download



Copyright Disclaimer:
This site does not store any files on its server. We only index and link to content provided by other sites. Please contact the content providers to delete copyright contents if any and email us, we'll remove relevant links or contents immediately.