
Ultimate access to all questions.
Your organization runs a mission-critical workload in a highly regulated industry. Sensitive data is uploaded from endpoint computers to Cloud Storage and then processed by Compute Engine VMs. A compliance review has found that the current setup does not meet data protection requirements. You must implement a solution that fulfills the following:
What two actions should you take?*
A
Configure Customer Managed Encryption Keys to encrypt the sensitive data before it is uploaded to Cloud Storage, and decrypt the sensitive data after it is downloaded into your VMs.
B
Configure Cloud External Key Manager to encrypt the sensitive data before it is uploaded to Cloud Storage, and decrypt the sensitive data after it is downloaded into your VMs.
C
Create Confidential VMs to access the sensitive data.
D
Migrate the Compute Engine VMs to Confidential VMs to access the sensitive data.
E
Create a VPC Service Controls service perimeter across your existing Compute Engine VMs and Cloud Storage buckets.