Google ACE Configuring Access and Security Practice Question
A company wants to automate the rotation of encryption keys for Cloud Storage buckets every 30 days. Which key type should be used?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Customer-Managed Encryption Keys (CMEK)
Customer-Managed Encryption Keys (CMEK) allow you to control the key lifecycle, including rotation. Google-Managed keys rotate automatically but you cannot schedule or force rotation. CSEK requires manual rotation. Key Access Justification is a feature of CMEK for access transparency.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Customer-Managed Encryption Keys (CMEK)
Why this is correct
Customer-Managed Encryption Keys (CMEK) is correct because it lets you control and automate key rotation through Cloud KMS. You define a rotation period (e.g., 30 days) on a key, and Cloud KMS automatically generates a new key version on that schedule while continuing to decrypt data with older versions. This provides both automated rotation and full auditability of when each version is used, which aligns with a company's requirement to rotate encryption keys without manual intervention.
- ✗
Google-managed encryption keys
Why it's wrong here
Google-managed encryption keys are not correct because, although Google automatically rotates these keys on a regular basis, the rotation schedule is entirely controlled by Google and is not exposed or adjustable by customers. You cannot set a specific rotation period or force a rotation, so the company would lack the ability to enforce its own compliance-driven rotation policies.
- ✗
Key Access Justification
Why it's wrong here
Key Access Justification is not correct because it is a feature of Cloud KMS that provides cryptographic justification logs showing why a key was accessed, primarily for controlled-access situations. It does not perform or automate rotation; it only enhances visibility and auditability of key usage, leaving rotation management separate and unaffected by this feature.
- ✗
Customer-Supplied Encryption Keys (CSEK)
Why it's wrong here
Customer-Supplied Encryption Keys (CSEK) is not correct because CSEK requires you to provide your own key material, which you must manage, upload, and rotate manually. There is no built-in automated rotation mechanism in CSEK, so using it would impose the opposite of the company's desired automation—requiring manual periodic updates to rotate the keys.
Go deeper
Related to this question
About these practice questions
Courseiva writes every ACE question from scratch — 769 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This ACE practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the ACE exam.