Step 7. Enable Encryption
[This step applies only if you have selected the Restore to new location, or with different settings option at the Restore Mode step of the wizard]
At the Encryption step of the wizard, choose whether the restored persistent disks will be encrypted with Google Cloud Key Management Service (Cloud KMS) customer-managed encryption keys (CMEKs):
- If you do not want to encrypt the persistent disks or want to apply the existing encryption scheme, select the Use original encryption scheme option.
- If you want to encrypt the persistent disks, select the Use customer-managed encryption key from Google Cloud KMS option and choose the necessary CMEK from the Encryption key drop-down list.
For a CMEK to be displayed in the list of available encryption keys, it must be stored in the region selected at step 6 of the wizard.