Courseiva

Google ACE Configuring Access and Security Practice Question

A company wants to automate the rotation of encryption keys for Cloud Storage buckets every 30 days. Which key type should be used?

⚠ Common exam trap

The trap is assuming that setting a rotation schedule on CMEK automatically re-encrypts existing data — it does not; rotation only creates new key versions, and existing objects must be rewritten to use them.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Customer-Managed Encryption Keys (CMEK)

Customer-Managed Encryption Keys (CMEK) allow the customer to control the key lifecycle, including rotation, through Cloud KMS. Because the customer owns and manages the key in KMS, they can set a rotation schedule (e.g., every 30 days) and automate it. Google-managed keys are rotated automatically by Google on a schedule the customer cannot control, and CSEK keys are supplied per-request and cannot be rotated by a schedule.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Customer-Managed Encryption Keys (CMEK)

    Why this is correct

    Customer-Managed Encryption Keys (CMEK) is correct because it lets you control and automate key rotation through Cloud KMS. You define a rotation period (e.g., 30 days) on a key, and Cloud KMS automatically generates a new key version on that schedule while continuing to decrypt data with older versions. This provides both automated rotation and full auditability of when each version is used, which aligns with a company's requirement to rotate encryption keys without manual intervention.

  • ✗

    Google-managed encryption keys

    Why it's wrong here

    Google-managed encryption keys are not correct because, although Google automatically rotates these keys on a regular basis, the rotation schedule is entirely controlled by Google and is not exposed or adjustable by customers. You cannot set a specific rotation period or force a rotation, so the company would lack the ability to enforce its own compliance-driven rotation policies.

  • ✗

    Key Access Justification

    Why it's wrong here

    Key Access Justification is not correct because it is a feature of Cloud KMS that provides cryptographic justification logs showing why a key was accessed, primarily for controlled-access situations. It does not perform or automate rotation; it only enhances visibility and auditability of key usage, leaving rotation management separate and unaffected by this feature.

  • ✗

    Customer-Supplied Encryption Keys (CSEK)

    Why it's wrong here

    Customer-Supplied Encryption Keys (CSEK) is not correct because CSEK requires you to provide your own key material, which you must manage, upload, and rotate manually. There is no built-in automated rotation mechanism in CSEK, so using it would impose the opposite of the company's desired automation—requiring manual periodic updates to rotate the keys.

About these practice questions

Courseiva writes every ACE question from scratch — 775 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Google Cloud exam blueprint

This ACE practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the ACE exam.