Associate Cloud Workspace Administrator · Free Practice Question Medium
Question 23
Your organization requires that all files stored in Google Drive must be encrypted with keys that are managed and rotated by the organization, not just by Google's default encryption mechanisms. What should you do to meet this requirement?
-
A
Enable S/MIME encryption for Gmail.
-
B
Implement Data Loss Prevention (DLP) rules for Drive and Docs.
-
C
Use Google Workspace Client-side encryption.
-
D
Turn on Information Rights Management (IRM) in Drive settings.
Reveal correct answer
Correct answer: C
A. Enabling S/MIME encryption for Gmail is related to email encryption, not file encryption in Google Drive. While it enhances email security, it does not address the requirement of encrypting files stored in Google Drive with organization-managed keys.
B. Implementing Data Loss Prevention (DLP) rules for Drive and Docs helps prevent the accidental sharing of sensitive information, but it does not specifically address the encryption of files stored in Google Drive with organization-managed keys. DLP rules focus on data protection and compliance, rather than encryption.
C. Using Google Workspace Client-side encryption allows you to encrypt files stored in Google Drive with keys managed and rotated by the organization. This ensures that the organization has full control over the encryption keys and provides an additional layer of security beyond Google's default encryption mechanisms.
D. Turning on Information Rights Management (IRM) in Drive settings allows you to control who can access, view, and edit files in Google Drive, but it does not directly address the requirement of encrypting files with organization-managed keys. IRM focuses on access control and permissions, rather than encryption.
Discussion
Think the marked answer is wrong, or have a better explanation? Share it below — comments appear after review.
