Google Cloud Professional Cloud Security Engineer Practice Exam

Question: 1 / 400

What is the best method to ensure compliance with FIPS 140-2 for a messaging app using GCP services?

Use Local SSDs exclusively for all data storage

Encrypt all cache storage and communications with BoringCrypto

To ensure compliance with FIPS 140-2, the correct approach would be to encrypt all cache storage and communications with BoringCrypto. FIPS 140-2 stipulates specific requirements for cryptographic modules that protect sensitive data. By using a FIPS-validated cryptographic library like BoringCrypto, which is designed to meet those regulatory standards, you can make sure that all data in transit and at rest is secured using algorithms and key management practices that are recognized for compliance.

This method directly addresses the need for strong encryption standards inherent in FIPS 140-2. Ensuring that both cache storage and communications are encrypted aligns with the compliance requirements for protecting sensitive information throughout its lifecycle.

In contrast, relying on local SSDs for data storage, implementing firewall rules, or establishing a VPN may provide security benefits but do not specifically address the requirement for FIPS-compliant encryption. While firewalls can protect network boundaries and VPNs secure communications, neither of these measures guarantee that the data is encrypted in a manner compliant with FIPS 140-2 standards. Thus, they do not serve as a complete solution for ensuring compliance in the context of this messaging app.

Get further explanation with Examzify DeepDiveBeta

Enable firewall rules on all Compute Engine instances

Implement VPN for all external communications

Next Question

Report this question

Subscribe

Get the latest from Examzify

You can unsubscribe at any time. Read our privacy policy