
Ultimate access to all questions.
To comply with your company's security initiative requiring customer-managed encryption keys for all Google Cloud data, you plan to use Cloud Key Management Service (KMS) while adhering to the "separation of duties" principle and Google's best practices. What are two actions you should take? (Choose two.)
A
Provision Cloud KMS in its own project.
B
Do not assign an owner to the Cloud KMS project.
C
Provision Cloud KMS in the project where the keys are being used.
D
Grant the roles/cloudkms.admin role to the owner of the project where the keys from Cloud KMS are being used.
E
Grant an owner role for the Cloud KMS project to a different user than the owner of the project where the keys from Cloud KMS are being used.