How to Encrypt Data While In Use in Google Cloud?

Data Protection & Confidential Computing
Answer Correct answer: B — Deploy Confidential VMs to establish a trusted execution environment that encrypts data while it is actively processed in memory.

Your organization operates in a highly regulated environment and has a stringent set of compliance requirements for protecting customer data. You must encrypt data while in use to meet regulations. What should you do?

  1. Enable the use of customer-supplied encryption keys (CSEK) keys in the Google Compute Engine VMs to give your organization maximum control over their VM disk encryption.
  2. Establish a trusted execution environment with a Confidential VM. Correct Answer
  3. Use a Shielded VM to ensure a secure boot with integrity monitoring for the application environment.
  4. Use customer-managed encryption keys (CMEK) and Cloud KSM to enable your organization to control their keys for data encryption in Cloud SQL.

Community Votes

B
100%

100% of anonymous learners picked answer B. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

Tests understanding of data encryption states, specifically distinguishing in-use protection from at-rest options like CMEK or CSEK.

Protecting data while in use requires hardware-based isolation and encryption in memory. This page confirms that Confidential VMs are the correct Google Cloud service for meeting strict regulatory requirements for in-use data protection.

Candidates often select CMEK or CSEK because they are familiar with disk encryption, but these only protect data at rest, not in active memory.

Community Discussion (3 comments)

Pime13 👍 1 Selected: B
https://cloud.google.com/confidential-computing/confidential-vm/docs/confidential-vm-overview
jmaquino 👍 2
B: https://cloud.google.com/security/products/confidential-computing?hl=es-419
abdelrahman89 👍 3 Selected: B
Answer B

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

Confidential VMs leverage hardware-based Trusted Execution Environments (TEEs) to isolate applications and encrypt data while it resides in active memory. This architecture directly satisfies the requirement to protect data during processing, which is critical for highly regulated compliance frameworks. By offloading cryptographic operations to a secure enclave, Google Cloud ensures that even privileged users cannot access plaintext data in RAM. Consequently, establishing a trusted execution environment with a Confidential VM is the only native control that addresses in-use encryption.

Why the Other Options Are Wrong

Customer-supplied encryption keys (CSEK) and customer-managed encryption keys (CMEK) exclusively secure data at rest on persistent disks or databases, leaving active memory unprotected. Shielded VMs focus on verifying boot integrity and preventing virtualization-based attacks through measured startup processes, rather than encrypting live application data. Since the prompt explicitly mandates encryption during active usage, both key management solutions and secure boot features fall outside the required scope.

Community Comment Notes

Learners consistently validated option B by referencing official vendor documentation on hardware-isolated workloads. As noted by jmaquino, the shared link points directly to the confidential computing product suite for memory protection. Pime13 reinforced this by sharing the official overview page detailing how trusted execution environments safeguard sensitive workloads. Multiple commenters echoed that selecting this configuration aligns perfectly with regulatory demands for in-memory data security.

Official Reference

Exam Strategy

Always map the three data encryption states (at rest, in transit, in use) to their corresponding Google Cloud controls before eliminating options. When a scenario emphasizes regulatory compliance for active processing, immediately prioritize hardware-isolated workloads over traditional key management or boot verification features.

Frequently Asked Questions

Why can't I use CMEK to encrypt data while in use?

CMEK secures data at rest on disks and backups, not active memory. Confidential VMs handle in-use encryption via hardware TEEs.

Is Shielded VM sufficient for regulatory in-use data protection?

No. Shielded VMs verify secure boot and protect against rootkits, but they do not encrypt data processing in RAM.

Related Analysis

← Back to PCSE Study Guide