Cloud Key Management Service: Incorrect Statement | CDL Exam Question | Google

Cloud Key Management Service Capability: Incorrect Statement

Question

Your organization is using Cloud Key Management Service to perform cryptographic operations. Identify the incorrect statement with regards to Cloud Key Management Service capability.

Answers

Explanations

Click on the arrows to vote for the correct answer

A. B. C. D.

Correct Answer: B.

Option A is incorrect.

Application-level encryption on Memorystore can be performed using Cloud Key Management Service.

Option B is correct.

Third-party software is not needed to implement PCI Data Security Standard Compliance.

Option C is incorrect.

Encryption and decryption of data with symmetric keys can be performed using Cloud Key Management Service.

Option D is incorrect.

Encryption and decryption of data with asymmetric keys can be performed using Cloud Key Management Service.

https://cloud.google.com/kms/docs#use-cases

The incorrect statement with regards to Cloud Key Management Service capability is:

A. Performing Application-level encryption on Memorystore.

Explanation:

  1. Cloud Key Management Service (KMS) is a cloud-hosted key management service that lets you manage cryptographic keys and perform cryptographic operations in a single, centralized cloud service.
  2. Cloud KMS allows you to create, use, rotate, and destroy cryptographic keys to protect your cloud services and resources.
  3. Cloud KMS supports symmetric and asymmetric keys, and can perform encryption and decryption of data using both types of keys.
  4. Cloud KMS can also integrate with other Google Cloud services, such as Memorystore, to perform cryptographic operations.
  5. However, Cloud KMS does not perform application-level encryption on Memorystore. Memorystore is a managed in-memory data store service, and Cloud KMS is used to manage cryptographic keys and perform cryptographic operations, but not to provide application-level encryption on Memorystore.
  6. Option A is therefore incorrect.
  7. Option B is a valid statement, as Cloud KMS supports the use of third-party software to implement PCI DSS compliance.
  8. Option C is also a valid statement, as Cloud KMS can perform encryption and decryption of data with symmetric keys.
  9. Option D is also a valid statement, as Cloud KMS can perform encryption and decryption of data with asymmetric keys.

Therefore, the correct answer is A. Performing Application-level encryption on Memorystore.