Configuring Access Approval with an External HSM Signing Key

Google Cloud Security & Identity
Answer Correct answer: C — Create a signing key in your external HSM, integrate it with Cloud External Key Manager, and configure Access Approval to use the provisioned key.

Your organization operates in a highly regulated industry and needs to implement strict controls around temporary access to sensitive Google Cloud resources. You have been using Access Approval to manage this access, but your compliance team has mandated the use of a custom signing key. Additionally, they require that the key be stored in a hardware security module (HSM) located outside Google Cloud. You need to configure Access Approval to use a custom signing key that meets the compliance requirements. What should you do?

  1. Create a new asymmetric signing key in Cloud Key Management System (Cloud KMS) using a supported algorithm and grant the Access Approval service account the IAM signerVerifier role on the key.
  2. Export your existing Access Approval signing key as a PEM file. Upload the file to your external HSM and reconfigure Access Approval to use the key from the HSM.
  3. Create a signing key in your external HSM. Integrate the HSM with Cloud External Key Manager (Cloud EKM) and make the key available within your project. Configure Access Approval to use this key. Correct Answer
  4. Create a new asymmetric signing key in Cloud KMS and configure the key with a rotation period of 30 days. Add the corresponding public key to your external HSM.

Community Votes

C
100%

100% of anonymous learners picked answer C. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

Tests external key integration for Access Approval, with the common trap being the selection of native Cloud KMS instead of the EKM bridge required for off-cloud HSMs.

This question tests configuring Google Cloud Access Approval with a custom signing key stored outside Google Cloud. The page establishes that Cloud External Key Manager (EKM) is required to bridge external hardware security modules with Access Approval.

Option A is frequently chosen by candidates who overlook the explicit 'outside Google Cloud' compliance constraint, mistakenly assuming standard Cloud KMS suffices.

Community Discussion (3 comments)

JohnDohertyDoe 👍 1 Selected: C
https://cloud.google.com/assured-workloads/access-approval/docs/review-approve-access-requests-custom-keys#select-key
BondleB 👍 1 Selected: C
Only option C fulfils the compliance requirement of custom signing key located outside google cloud.
yokoyan 👍 3 Selected: C
I think it's C.

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

Access Approval natively supports custom signing keys to satisfy strict regulatory requirements. When compliance mandates that the key reside outside Google Cloud, Cloud External Key Manager (EKM) serves as the mandatory integration layer. EKM allows your project to reference and utilize cryptographic materials hosted in an external HSM without exposing private key material to Google’s infrastructure. Selecting this path ensures full alignment with the stated compliance mandate while maintaining seamless approval workflows.

Why the Other Options Are Wrong

Option A incorrectly utilizes native Cloud KMS, which stores keys within Google Cloud and directly violates the explicit off-cloud storage requirement. Option B suggests exporting a PEM file, but Access Approval does not accept raw PEM uploads due to strict lifecycle management and audit logging requirements. Option D mixes internal key rotation with external public key placement, which breaks the cryptographic signing chain required for approval validation.

Community Comment Notes

As JohnDohertyDoe linked to the official review page, the workflow requires EKM integration for custom keys. BondleB highlighted that "Only option C fulfils the compliance requirement" by pointing out the external HSM constraint. Learners like yokoyan agreed after ruling out native KMS alternatives.

Official Reference

Exam Strategy

Always scan for geographic or infrastructure constraints like 'outside Google Cloud' before selecting key management services. Match the requirement to the correct architectural component—Cloud EKM is exclusively designed to bridge external HSMs with GCP services.

Frequently Asked Questions

Why can't I import the PEM file directly into Access Approval?

Access Approval does not support direct PEM imports; it relies on KMS or EKM integrations to manage key lifecycle and permissions securely.

Does Cloud EKM keep my external HSM key inside Google Cloud?

No, EKM acts as a bridge. The actual key material remains in your external HSM, while EKM provides authorized access points within your GCP project.

Related Analysis

← Back to PCSE Study Guide