Be able to map a stated compliance, residency, or privacy requirement to the right service: Cloud KMS or Cloud HSM for keys, Secret Manager for credentials, Cloud DLP for sensitive data, and organization policy for location. The key skill is distinguishing inspection from de-identification and default from customer-managed encryption.
Start practicing
Ensuring Data Protection — choose a session length
Free · No account required
Domain overview
This domain covers how Google Cloud protects data at rest, in use, and in transit: Cloud KMS and Cloud HSM, Secret Manager, Cloud DLP, encryption options, and data residency controls. Questions are scenario-based, asking you to pick the correct service, IAM role, or organization policy for a stated compliance or privacy requirement.
Exam objectives
Choosing Cloud KMS key rings, key versions, and rotation schedules versus Cloud HSM for FIPS 140-2 Level 3 key protection.
Using Cloud DLP de-identification transforms like masking, tokenization, and format-preserving encryption on BigQuery and Cloud Storage data.
Configuring Secret Manager secret versions, rotation schedules, and Pub/Sub notifications for automated credential rotation.
Enforcing data residency with organization policy constraints such as constraints/gcp.resourceLocations on projects and folders.
Assuming default Google-managed encryption keys satisfy requirements that explicitly demand customer-managed keys, CMEK, or HSM-backed keys.
Confusing Cloud DLP inspection, which only finds sensitive data, with de-identification transforms, which actually mask or tokenize it.
Believing IAM alone enforces region restrictions, when location control requires organization policy constraints applied at project or folder level.
Click any question to see the full explanation and answer options, or start a focused practice session above.
A company uses Cloud KMS with a key purpose of ENCRYPT_DECRYPT. They need to rotate the key automatically every 30 days. What must they configure?
2Which Google Cloud service provides near-real-time logs when Google administrators access your customer content?
3A company stores API keys in Secret Manager. They want to automatically rotate the secret every 60 days and have a Cloud Function triggered after each rotation to update dependent services. What is the correct approach?
4An organization needs to enforce that all new Cloud Storage buckets are created only in the europe-west1 region to meet data residency requirements. Which method should they use?
5A financial services company uses BigQuery for analytics and needs to implement column-level security such that users with the role 'data_scientist' can see the last four digits of credit card numbers, while the full number is visible only to 'data_owner'. What approach should they use?
6What is the purpose of the Cloud DLP InfoType detector CREDIT_CARD_NUMBER?
7A company uses Customer-Supplied Encryption Keys (CSEK) for Compute Engine persistent disks. They want to ensure that Google does not store the key material. What must they do?
8A company uses Assured Workloads to meet FedRAMP High compliance in the US. They need to ensure that data cannot be moved outside the US region. Which control should they use?
9Which two statements correctly describe Cloud KMS key versions? (Choose TWO.)
10An organization wants to encrypt data at rest using customer-managed keys on Compute Engine persistent disks. They need to provide the key material with each API call, and Google should never store the key. Which encryption approach should they use?
11A security engineer wants to automatically rotate a database password stored in Secret Manager every 30 days. The new password should be generated and stored in Secret Manager without manual intervention. Which approach meets these requirements?
12A healthcare company stores patient data in BigQuery and needs to mask sensitive columns like SSN and email for analysts who do not need to see the actual values. They want to apply consistent masking across queries without modifying the underlying data. Which feature should they use?
13A company uses Cloud KMS with an HSM key for encryption of sensitive data. The compliance team requires that the key material never leaves the HSM boundary. They plan to use the key for symmetric encryption/decryption. Which key purpose should they specify when creating the key?
14A data engineer needs to scan a Cloud Storage bucket for personally identifiable information (PII) such as credit card numbers and social security numbers. The scanning must be performed on a schedule (every week). Which GCP service and resource should they use?
15A financial institution is required to store customer transaction data within the European Union to comply with GDPR data residency requirements. They want to prevent users from creating resources in any region outside the EU. Which organization policy constraint should they use?
16A company uses Cloud KMS with automatic rotation enabled for a symmetric key. The rotation period is set to 90 days. After 90 days, a new key version is created. The compliance team asks: what happens to data encrypted with the old key version?
17An organization wants to use a FIPS 140-2 Level 3 validated hardware security module (HSM) to protect encryption keys in Cloud KMS. Which key protection level should they choose when creating a key ring?
18A data scientist needs to access a secret stored in Secret Manager from a Compute Engine VM. The VM has the default service account attached. Which IAM role should be granted to the service account to allow reading the secret?
19A company uses Cloud DLP to inspect BigQuery tables for sensitive data. They want to automatically de-identify the data before loading it into another BigQuery dataset for analysis. Which THREE components must be configured? (Choose three.)
20A company wants to encrypt data at rest in Cloud Storage using a key that they manage and rotate periodically. They also need to ensure that the key material is stored in a FIPS 140-2 Level 3 validated HSM. Which encryption option should they use?
21A security engineer needs to store database credentials and API keys securely in GCP. The solution must support automatic rotation of secrets at a defined schedule and trigger a Cloud Function after each rotation to update dependent applications. Which service should they use?
22A security engineer needs to enforce that all new Compute Engine disks are created in a specific geographic region to meet data residency requirements. Which organization policy constraint should they use?
23A company uses Cloud KMS with a key purpose of ENCRYPT_DECRYPT. They want to rotate the key automatically every 90 days. What must the security engineer configure to achieve this?
24A company uses CMEK with Cloud HSM to encrypt a BigQuery table. The security engineer accidentally deleted the key in Cloud KMS. The key is now in a 'pending destruction' state with a grace period of 24 hours. Which action should the engineer take to restore the key and avoid data loss?
25A company wants to use Cloud DLP to inspect Cloud Storage buckets for phone numbers that match a custom pattern (e.g., +1-XXX-XXX-XXXX). The pattern is not covered by built-in infoTypes. How should the engineer configure the DLP job?
26A security engineer needs to view logs of Google Cloud support engineers accessing their data to meet compliance requirements. Which GCP feature should they enable?
27A security engineer needs to implement de-identification of sensitive data in a Cloud Storage bucket using Cloud DLP. They want to inspect the data for credit card numbers and then replace them with a tokenized value that preserves the format for downstream processing. Which TWO actions should they take? (Choose two.)
28A company must comply with regulatory requirements that restrict data access by Google Cloud support and engineering staff. They need to log all Google admin access to their data and also require explicit approval before access is granted. Which TWO features should they combine? (Choose two.)
29An organization needs to store API keys and database credentials in a central, auditable service with versioning and IAM access control. Which GCP service should they use?
30A company uses Cloud DLP to scan a BigQuery table for sensitive data. They want to automatically mask credit card numbers in query results for users who are not data stewards. Which approach should they use?
31A financial institution must store data in specific EU regions to comply with GDPR. They want to prevent users from creating resources in other regions. Which organization policy should they set?
32A security engineer needs to audit all administrative actions performed by Google support engineers on their GCP project. Which service provides near-real-time logs of such access?
33Which Cloud KMS key purpose should be used to encrypt and decrypt data directly?
34An engineer needs to schedule automatic rotation of a symmetric key in Cloud KMS every 30 days. The key is currently enabled. What should they do?
35An organization needs to de-identify a BigQuery column containing US Social Security Numbers (SSNs) by replacing them with a consistent token that can be reversed if needed. Which Cloud DLP de-identification transform should they use?
36A security team wants to automatically rotate a database password stored in Secret Manager every 60 days and notify the operations team when a new version is created. Which approach should they use?
37A company is subject to ITAR regulations and needs to ensure that all data stored in GCP remains within the United States. They also require FIPS 140-2 Level 3 validation for encryption keys. Which two services should they use together to meet these requirements? (Choose 2)
38An organization wants to ensure that all new resources created in Google Cloud are restricted to a specific set of regions to meet data residency requirements. Which policy should they use?
39A security engineer needs to automatically rotate a database password stored in Secret Manager every 60 days. Which approach meets this requirement with minimal operational overhead?
40An organization needs to store API keys for external services. Which Google Cloud service is designed for secure storage of secrets such as API keys, passwords, and certificates?
41A company wants to enforce that all Compute Engine disk encryption uses keys managed by their own HSM on-premises, with keys provided per API call. Which encryption type should they choose when creating a persistent disk?
42An organization needs to audit when Google administrators access their customer content stored in GCP. Which service provides near-real-time logs of such access?
43A data engineer wants to classify columns in BigQuery containing sensitive data like email addresses and apply data masking so that users see only masked values (e.g., 'j***@example.com'). Which feature should they use?
44A company using Cloud KMS wants to automatically rotate a symmetric encryption key every 90 days. What is the correct way to configure this?
45An organization needs to store cryptographic keys that must be protected in a FIPS 140-2 Level 3 validated hardware security module (HSM). Which Google Cloud service should they use?
46A company needs to enforce data residency in the European Union for all GCP resources. Which TWO actions should they take? (Choose two.)
47An organization needs to store API keys and database credentials in a secure, centralized service that supports automatic rotation and integrates with Cloud Functions. The solution must provide fine-grained access control at the secret version level. Which service should they use?
48A company wants to enforce that all new Cloud Storage buckets are created in only the europe-west1 region. Which organization policy constraint should they use?
49What is the purpose of Cloud HSM?
50A security engineer wants to enable Access Transparency for their organization. After enabling it in the Admin Console, they notice that some access logs are missing. What is the most likely reason?
51Which Cloud DLP transform should be used to replace sensitive data with a token that preserves the format and length of the original data for reversible de-identification?
52An organization needs to comply with ITAR regulations. They want to ensure that all data processed by their GCP resources remains within the United States. Which service should they use?
53An organization stores sensitive customer data in BigQuery tables. They need to enforce column-level security such that users in the 'support' group see a masked version of email addresses (e.g., j***@example.com), while managers see the full email. Which approach should they use?
54A company uses Cloud DLP to inspect data in Cloud Storage and BigQuery for sensitive information such as credit card numbers and social security numbers. They want to de-identify the data using format-preserving encryption (FPE) so that the masked data retains the same format (e.g., a 16-digit number still looks like a credit card number). Which two configurations should they use? (Choose TWO).
55A company wants to use Cloud KMS to protect sensitive data. They have a requirement that the key material must be stored in a FIPS 140-2 Level 3 validated HSM. They also need to be able to create and use asymmetric keys for signing. Which two steps should they take? (Choose TWO).
56A company needs to detect and redact sensitive data such as email addresses and phone numbers from documents stored in Cloud Storage. They plan to use Cloud DLP. Which two resources must they create first? (Choose TWO).
57A company is designing a key destruction process for Cloud KMS. They need to ensure that after a key is destroyed, the ciphertext encrypted with that key becomes permanently undecryptable. They also need to allow a 7-day recovery window in case of accidental destruction. Which three steps should they take? (Choose THREE).
58A security team needs to monitor and log all Google Cloud administrator access to customer data stored in Cloud Storage and BigQuery. They want to receive near-real-time alerts when such access occurs. Which two services should they use together? (Choose TWO).
59A media company stores video assets in a Cloud Storage bucket. They want to ensure that all objects in the bucket are encrypted with a Customer-Managed Encryption Key (CMEK) rather than the default Google-managed encryption. They also need to prove to auditors that CMEK is enforced and cannot be bypassed. What should they do?
60A healthcare company stores patient records in Cloud Storage. They must ensure that data is encrypted at rest with keys they fully control, and that keys are automatically rotated every 90 days. They also need to be able to immediately revoke access to the data by disabling the key. Which approach should they use?
61A healthcare analytics team stores patient records in Cloud Storage. They need to grant an external research partner read access to only specific objects that contain aggregated, de-identified data, while ensuring the partner cannot list or discover any other objects in the bucket. The partner has their own Google Cloud identity. What should the security engineer do?
62A healthcare analytics company stores patient records in Cloud Storage. Their compliance team mandates that all objects be encrypted with a Customer-Managed Encryption Key (CMEK) that the company can revoke at any time. They also require that the encryption key be generated and stored in a FIPS 140-2 Level 3 validated HSM. Which approach should they use?
63A startup stores user credentials in a Cloud SQL database. They want to ensure that the database password is never hardcoded in application code and is automatically rotated every 60 days. Which Google Cloud service should they use to store and rotate the password?
64A healthcare analytics team stores protected health information (PHI) in Cloud Storage buckets. They need to ensure that PHI is de-identified before it is written to the bucket, and they want to monitor for any accidental uploads of raw PHI. They are using Cloud DLP for inspection and de-identification. Which approach should they implement to meet both requirements?
65A company stores sensitive data in Cloud Storage and wants to ensure that all data is encrypted at rest with keys that they control and can rotate. They also need to be able to audit key usage. Which two Google Cloud services should they use? (Choose two.)
66A company needs to encrypt data at rest in BigQuery using a customer-managed encryption key (CMEK) so that they can control key rotation and revocation. They want to use Cloud KMS. Which of the following must they do to use CMEK with BigQuery?
67A company needs to store database connection strings and API keys for its applications running on Compute Engine. The security team requires that these secrets be encrypted at rest, automatically rotated, and accessible only to specific service accounts. Which Google Cloud service should they use?
68A company needs to store sensitive configuration data, such as database credentials, in Google Cloud. They require that the data be encrypted at rest and in transit, and that access be auditable. They also want to minimize management overhead. Which Google Cloud service should they use?
69A healthcare analytics team stores patient records in Cloud Storage and BigQuery. Auditors require that sensitive fields like patient names and medical record numbers be replaced with surrogate values before analysts can query the data, but the same surrogate value must consistently map back to the original patient across all datasets so longitudinal studies remain valid. Which Cloud DLP de-identification technique should the team apply?
70A security engineer needs to ensure that data stored in a Cloud SQL for MySQL instance is encrypted at rest with a key that the company can rotate and disable independently of Google. What should they do?
71A company stores sensitive customer data in Cloud Storage buckets. They need to ensure that data is encrypted at rest with a key that they manage themselves, and that the key material is generated and stored in a hardware security module (HSM) that meets FIPS 140-2 Level 3. They also require automatic rotation every 90 days. Which solution should they use?
72Your organization stores large volumes of sensitive data in Cloud Storage. A security policy requires that all data be encrypted with customer-managed encryption keys (CMEK) at rest, and that the keys be automatically rotated every 90 days. You need to enforce this for all new objects written to a specific bucket. What should you do?
73A security engineer needs to ensure that data stored in Cloud Storage is encrypted with a customer-supplied encryption key (CSEK) that is never stored in Google Cloud. They want to use the JSON API to upload objects. Which of the following is required to use CSEK with the JSON API?
74Your security team must ensure that a Cloud Storage bucket containing regulated customer data is encrypted with a customer-managed encryption key (CMEK) stored in Cloud KMS, and that the key is automatically rotated every 90 days. You have created a key ring and a symmetric key in Cloud KMS. Which configuration step is required to meet the automatic rotation requirement?
75A company needs to store database credentials for a legacy application. The credentials must be encrypted at rest, automatically rotated every 60 days, and accessed by applications running on Compute Engine instances. Which Google Cloud service should they use?
76A healthcare analytics company stores patient records in Cloud Storage. Regulatory requirements mandate that all data be encrypted with customer-managed encryption keys (CMEK) and that the encryption keys be automatically rotated every 90 days. They also need the ability to revoke access to the data immediately if a key is compromised. Which Google Cloud service should they use to centrally manage and rotate these keys?
77A security engineer needs to ensure that data stored in a Cloud SQL for MySQL instance is encrypted at rest with a key that the organization controls and can rotate. The organization already uses Cloud KMS. What is the simplest way to achieve this?
78A company is using Cloud DLP to inspect and de-identify sensitive data in a Cloud Storage bucket. They need to ensure that the de-identification process is reversible for authorized users, but irreversible for others. They plan to use Cloud DLP's cryptographic transformation methods. Which two methods should they use? (Choose two.)
79A company uses Cloud DLP to inspect a Cloud Storage bucket containing JSON files for sensitive data. They want to redact all email addresses and phone numbers found in the files, replacing them with the string '[REDACTED]', and then write the de-identified files to a new bucket. Which Cloud DLP configuration should they use?
80A security administrator needs to grant a team of auditors read-only access to all current and future objects in a Cloud Storage bucket named 'audit-logs' in a project. The auditors should not be able to modify or delete any objects. Which IAM role should the administrator grant to the auditors at the bucket level?
81A financial services firm stores sensitive customer data in Cloud Storage. They want to use Cloud DLP to inspect and de-identify data before it is written to a BigQuery dataset. The data includes names, email addresses, and credit card numbers. They need to replace each detected sensitive value with a surrogate that preserves the original data type and length, and they must be able to reverse the transformation later using a separate key. Which Cloud DLP transformation should they use?
82A financial institution uses Cloud DLP to de-identify sensitive data in a BigQuery table before sharing it with an analytics team. They need to replace each email address with a surrogate value that is consistent across all rows, so that the same email always maps to the same surrogate, and the mapping cannot be reversed without additional information. Which Cloud DLP transformation should they use?
83A financial institution needs to store audit logs in Cloud Storage for 7 years to meet regulatory requirements. They must ensure that the logs cannot be deleted or modified by any user, including administrators, during that period. They also need to be able to prove compliance to auditors. Which Cloud Storage feature should they use?
84Your team stores sensitive customer records in Cloud Storage. A security policy requires that all data be encrypted with customer-managed encryption keys (CMEK) and that key usage be logged for audit. You create a Cloud KMS key ring and key in the same region as the bucket. Which additional configuration must you apply to the bucket to enforce CMEK encryption for all newly written objects?
85A company stores sensitive customer data in a Cloud SQL for PostgreSQL instance. They want to ensure that data is encrypted at rest using a customer-managed encryption key (CMEK) that they control and can rotate. They have created a Cloud KMS key ring and a symmetric key in the same region as the Cloud SQL instance. What should they do next to configure the Cloud SQL instance to use the CMEK?
86Your organization uses Cloud KMS to manage encryption keys for various Google Cloud services. A security policy mandates that all symmetric keys used for data at rest must be automatically rotated every 90 days and that old key versions must remain available for decryption for at least 30 days after rotation. How should you configure the key?
87A healthcare analytics company stores sensitive patient records in a Cloud Storage bucket. They need to ensure that data is encrypted with a key that they control, that the key material never leaves their on-premises HSM, and that all encryption and decryption operations are performed in their own environment. Which Cloud KMS feature should they use?
88A security engineer needs to ensure that data stored in a Cloud SQL for MySQL instance is encrypted with a customer-managed encryption key (CMEK) and that the key is rotated every 180 days. The engineer also needs to prove to auditors that the data is encrypted with the correct key. What should they do?
89A healthcare analytics company stores patient records in Cloud Storage buckets and BigQuery datasets. Compliance requires that all data be encrypted with customer-managed encryption keys (CMEK) that the company controls, and that key usage be auditable. The security team wants to ensure that any new object or table created without a CMEK is automatically encrypted with a default CMEK. What should they do?
90A company stores sensitive configuration data in Cloud Storage. They want to ensure that data is encrypted at rest using a key that they manage, and they want to be able to audit all key usage. Which Google Cloud service should they use to manage the encryption keys?
91A financial institution uses Cloud KMS to encrypt data at rest in BigQuery. They need to ensure that encryption keys are automatically rotated every 90 days, that old key versions are retained for decryption, and that key usage is logged. Which configuration should they implement?
92A company uses Cloud Storage to store sensitive documents. They need to ensure that all data is encrypted at rest with keys that are automatically rotated every 180 days and that they can audit key usage. Which Google Cloud service should they use to meet these requirements?
93A healthcare analytics company stores protected health information in Cloud Storage buckets. Compliance requires that data be encrypted with keys that the company generates and manages on-premises, and that all cryptographic operations occur outside Google Cloud. The security team must ensure the encryption keys never leave their own hardware security modules. Which Cloud KMS feature should they implement?
94A security team needs to ensure that sensitive data stored in Cloud Storage is protected against accidental public exposure. They want to automatically detect and remediate any bucket that becomes publicly accessible, and they need an audit trail of all such events. Which Google Cloud solution should they implement?
95A security engineer needs to store and manage API keys for a production application running on Compute Engine. The keys must be encrypted at rest and automatically rotated every 60 days. Which Google Cloud service should they use?
96A company uses Cloud DLP to inspect a BigQuery table for sensitive data. They want to replace all detected email addresses with a consistent token that can be used for joining with other tables, but they do not want to store the mapping. Which Cloud DLP transformation should they use?
97A security engineer is configuring Cloud KMS for a regulated workload and must ensure that key material is generated and protected inside a hardware security module, and that the keys can be used by workloads in a different Google Cloud project without copying key material. (Choose two.)
98A startup is developing a mobile app that needs to store user credentials for third-party APIs. They want a fully managed Google Cloud service that handles secret storage, versioning, and access control, with automatic replication across regions. Which service should they use?
99A company needs to store database credentials for a production application. The credentials must be encrypted at rest and in transit, and the application should retrieve them at runtime using its service account. Which Google Cloud service should they use?
100A media company stores raw interview footage in a Cloud Storage bucket that has Uniform Bucket-Level Access enabled. Legal requires that no object in the bucket be readable by anyone except a small investigations group, and that even project owners cannot grant themselves access. The security team wants a single control that enforces this regardless of future IAM changes. Which control should they apply?
101A security engineer at a retail company is configuring Cloud Storage bucket permissions. The company wants to ensure that only users with the role 'roles/storage.objectViewer' can read objects, but they also want to prevent any user from making objects publicly accessible, even if they have the 'roles/storage.objectAdmin' role. What should the engineer do?
102A security engineer is configuring a Cloud KMS key ring for a new application that processes highly sensitive data. The application requires that cryptographic keys be protected by hardware security modules that meet FIPS 140-2 Level 3, and that the keys be automatically rotated every 90 days. The engineer wants to minimize operational overhead. What should they do?
103A security engineer needs to ensure that data stored in a Cloud Storage bucket is protected against accidental deletion. The bucket contains compliance-related documents that must be retained for seven years. They enable Object Versioning and want to prevent any object version from being permanently deleted before the retention period expires. What should they configure?
104A company needs to store database credentials for its application in Google Cloud. The credentials must be encrypted at rest, accessible only to the application's service account, and automatically rotated every 60 days. Which Google Cloud service should they use?
105A company uses BigQuery to store customer data and wants to enforce that only users with the role 'data_viewer' can see a specific column containing personally identifiable information, while other columns remain accessible to a broader group. They also need to ensure that the policy is applied consistently even when data is queried through authorized views. Which BigQuery feature should they use?
106A security engineer needs to grant a service account permission to encrypt and decrypt data using a Cloud KMS symmetric key. The service account is used by an application running on Compute Engine. Which IAM role should be granted on the Cloud KMS key?
107Your organization uses VPC Service Controls to create a service perimeter around a project containing sensitive BigQuery datasets. You need to allow a specific set of data scientists to access the BigQuery data from outside the perimeter. They use a corporate network with a static IP address range. What should you configure to permit this access?
Be able to map a stated compliance, residency, or privacy requirement to the right service: Cloud KMS or Cloud HSM for keys, Secret Manager for credentials, Cloud DLP for sensitive data, and organization policy for location. The key skill is distinguishing inspection from de-identification and default from customer-managed encryption.
The Courseiva PCSE question bank contains 107 questions in the Ensuring Data Protection domain, covering the 23% of the exam attributed to this domain in the official Google Cloud blueprint. Click any question to see the full explanation and answer breakdown.
Start with a 10-question focused session to identify your baseline accuracy in this domain. Read every explanation — even for questions you answer correctly — to understand the reasoning. Once you score consistently above 80%, move to a 20–30 question session to confirm depth before moving to the next domain.
Yes — the session launcher on this page draws questions exclusively from the Ensuring Data Protection domain. Choose 10, 20, 30, or 50 questions for a focused session, or click individual questions to review them one by one.
Save your results, see per-domain analytics, and get readiness scores — free, for every certification.
Sign Up FreeFree forever · Every certification included