Google ACE Configuring Access and Security Practice Question
A company wants to automate the rotation of encryption keys for Cloud Storage buckets every 30 days. Which key type should be used?
⚠ Common exam trap
The trap is assuming that setting a rotation schedule on CMEK automatically re-encrypts existing data — it does not; rotation only creates new key versions, and existing objects must be rewritten to use them.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Customer-Managed Encryption Keys (CMEK)
Customer-Managed Encryption Keys (CMEK) allow the customer to control the key lifecycle, including rotation, through Cloud KMS. Because the customer owns and manages the key in KMS, they can set a rotation schedule (e.g., every 30 days) and automate it. Google-managed keys are rotated automatically by Google on a schedule the customer cannot control, and CSEK keys are supplied per-request and cannot be rotated by a schedule.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Customer-Managed Encryption Keys (CMEK)
Why this is correct
Customer-Managed Encryption Keys (CMEK) is correct because it lets you control and automate key rotation through Cloud KMS. You define a rotation period (e.g., 30 days) on a key, and Cloud KMS automatically generates a new key version on that schedule while continuing to decrypt data with older versions. This provides both automated rotation and full auditability of when each version is used, which aligns with a company's requirement to rotate encryption keys without manual intervention.
- ✗
Google-managed encryption keys
Why it's wrong here
Google-managed encryption keys are not correct because, although Google automatically rotates these keys on a regular basis, the rotation schedule is entirely controlled by Google and is not exposed or adjustable by customers. You cannot set a specific rotation period or force a rotation, so the company would lack the ability to enforce its own compliance-driven rotation policies.
- ✗
Key Access Justification
Why it's wrong here
Key Access Justification is not correct because it is a feature of Cloud KMS that provides cryptographic justification logs showing why a key was accessed, primarily for controlled-access situations. It does not perform or automate rotation; it only enhances visibility and auditability of key usage, leaving rotation management separate and unaffected by this feature.
- ✗
Customer-Supplied Encryption Keys (CSEK)
Why it's wrong here
Customer-Supplied Encryption Keys (CSEK) is not correct because CSEK requires you to provide your own key material, which you must manage, upload, and rotate manually. There is no built-in automated rotation mechanism in CSEK, so using it would impose the opposite of the company's desired automation—requiring manual periodic updates to rotate the keys.
Go deeper
Related to this question
Learn chapter
Google Cloud Platform Overview
Key term
Cloud storage
Cloud storage is a service that lets you save data on remote servers accessed over the internet instead of on your computer's hard drive.
Key term
Cloud KMS
Cloud KMS (Key Management Service) is a cloud-based service that lets you create, manage, and use encryption keys to protect your data at rest and in transit.
About these practice questions
Courseiva writes every ACE question from scratch — 775 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Google Cloud exam blueprint
This ACE practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the ACE exam.