How to Encrypt Data While In Use in Google Cloud?
Your organization operates in a highly regulated environment and has a stringent set of compliance requirements for protecting customer data. You must encrypt data while in use to meet regulations. What should you do?
Community Votes
100% of anonymous learners picked answer B. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
Tests understanding of data encryption states, specifically distinguishing in-use protection from at-rest options like CMEK or CSEK.
Protecting data while in use requires hardware-based isolation and encryption in memory. This page confirms that Confidential VMs are the correct Google Cloud service for meeting strict regulatory requirements for in-use data protection.
Candidates often select CMEK or CSEK because they are familiar with disk encryption, but these only protect data at rest, not in active memory.
Community Discussion (3 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
Confidential VMs leverage hardware-based Trusted Execution Environments (TEEs) to isolate applications and encrypt data while it resides in active memory. This architecture directly satisfies the requirement to protect data during processing, which is critical for highly regulated compliance frameworks. By offloading cryptographic operations to a secure enclave, Google Cloud ensures that even privileged users cannot access plaintext data in RAM. Consequently, establishing a trusted execution environment with a Confidential VM is the only native control that addresses in-use encryption.Why the Other Options Are Wrong
Customer-supplied encryption keys (CSEK) and customer-managed encryption keys (CMEK) exclusively secure data at rest on persistent disks or databases, leaving active memory unprotected. Shielded VMs focus on verifying boot integrity and preventing virtualization-based attacks through measured startup processes, rather than encrypting live application data. Since the prompt explicitly mandates encryption during active usage, both key management solutions and secure boot features fall outside the required scope.Community Comment Notes
Learners consistently validated option B by referencing official vendor documentation on hardware-isolated workloads. As noted by jmaquino, the shared link points directly to the confidential computing product suite for memory protection. Pime13 reinforced this by sharing the official overview page detailing how trusted execution environments safeguard sensitive workloads. Multiple commenters echoed that selecting this configuration aligns perfectly with regulatory demands for in-memory data security.Official Reference
Exam Strategy
Always map the three data encryption states (at rest, in transit, in use) to their corresponding Google Cloud controls before eliminating options. When a scenario emphasizes regulatory compliance for active processing, immediately prioritize hardware-isolated workloads over traditional key management or boot verification features.
Frequently Asked Questions
Why can't I use CMEK to encrypt data while in use?
CMEK secures data at rest on disks and backups, not active memory. Confidential VMs handle in-use encryption via hardware TEEs.
Is Shielded VM sufficient for regulatory in-use data protection?
No. Shielded VMs verify secure boot and protect against rootkits, but they do not encrypt data processing in RAM.