Courseiva
Configuring Access and SecurityeasyMultiple ChoiceObjective-mapped

Google ACE Configuring Access and Security Practice Question

A company wants to automate the rotation of encryption keys for Cloud Storage buckets every 30 days. Which key type should be used?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Customer-Managed Encryption Keys (CMEK)

Customer-Managed Encryption Keys (CMEK) allow you to control the key lifecycle, including rotation. Google-Managed keys rotate automatically but you cannot schedule or force rotation. CSEK requires manual rotation. Key Access Justification is a feature of CMEK for access transparency.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Customer-Managed Encryption Keys (CMEK)

    Why this is correct

    Customer-Managed Encryption Keys (CMEK) is correct because it lets you control and automate key rotation through Cloud KMS. You define a rotation period (e.g., 30 days) on a key, and Cloud KMS automatically generates a new key version on that schedule while continuing to decrypt data with older versions. This provides both automated rotation and full auditability of when each version is used, which aligns with a company's requirement to rotate encryption keys without manual intervention.

  • Google-managed encryption keys

    Why it's wrong here

    Google-managed encryption keys are not correct because, although Google automatically rotates these keys on a regular basis, the rotation schedule is entirely controlled by Google and is not exposed or adjustable by customers. You cannot set a specific rotation period or force a rotation, so the company would lack the ability to enforce its own compliance-driven rotation policies.

  • Key Access Justification

    Why it's wrong here

    Key Access Justification is not correct because it is a feature of Cloud KMS that provides cryptographic justification logs showing why a key was accessed, primarily for controlled-access situations. It does not perform or automate rotation; it only enhances visibility and auditability of key usage, leaving rotation management separate and unaffected by this feature.

  • Customer-Supplied Encryption Keys (CSEK)

    Why it's wrong here

    Customer-Supplied Encryption Keys (CSEK) is not correct because CSEK requires you to provide your own key material, which you must manage, upload, and rotate manually. There is no built-in automated rotation mechanism in CSEK, so using it would impose the opposite of the company's desired automation—requiring manual periodic updates to rotate the keys.

About these practice questions

Courseiva writes every ACE question from scratch — 769 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This ACE practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the ACE exam.