Courseiva

Google ACE Configuring Access and Security Practice Question

A company wants to use Customer-Managed Encryption Keys (CMEK) for a Cloud SQL instance. What must be done first?

⚠ Common exam trap

ACE often tests the misconception that enabling the Cloud KMS API or using a key file is sufficient for CMEK, but the critical step is granting the Cloud SQL service account the correct IAM role on the KMS key.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Create a Cloud KMS key ring and key, and grant the Cloud SQL service account the cloudkms.cryptoKeyEncrypterDecrypter role.

To use Customer-Managed Encryption Keys (CMEK) with Cloud SQL, you must first create a Cloud KMS key ring and key, then grant the Cloud SQL service account the cloudkms.cryptoKeyEncrypterDecrypter role. This allows Cloud SQL to use the key to encrypt the instance's data at rest. The service account must have permission to use the key for encryption and decryption operations.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Create a bucket and upload a key file.

    Why it's wrong here

    Storing a raw encryption key file in Cloud Storage does not implement CMEK for Cloud SQL. Cloud SQL uses Cloud KMS key resources (a key ring and a crypto key) for envelope encryption, not files in a bucket. Uploading a key file also introduces a security risk and lacks the IAM integration that the Cloud SQL service account needs to access the key.

  • ✓

    Create a Cloud KMS key ring and key, and grant the Cloud SQL service account the cloudkms.cryptoKeyEncrypterDecrypter role.

    Why this is correct

    This is the correct prerequisite for enabling CMEK on a Cloud SQL instance. You must create a key ring and a crypto key in Cloud KMS, then grant the Cloud SQL service account (e.g., service-<project>@gcp-sa-cloudsql.iam.gserviceaccount.com) the cloudkms.cryptoKeyEncrypterDecrypter role. That IAM binding lets Cloud SQL call Cloud KMS to encrypt and decrypt the data encryption keys used to protect the instance.

  • ✗

    Enable Cloud KMS API and use default encryption.

    Why it's wrong here

    Enabling the Cloud KMS API is necessary, but 'default encryption' uses Google-managed keys; CMEK requires you to explicitly create and specify a customer-managed key. Without creating a key and granting permissions, no CMEK is applied, and the Cloud KMS API alone does nothing to change how Cloud SQL encrypts data.

  • ✗

    Set the --disk-encryption-key flag to an existing key in Cloud KMS.

    Why it's wrong here

    The --disk-encryption-key flag is used when creating a Cloud SQL instance, but it only works if the key already exists and the Cloud SQL service account has the cloudkms.cryptoKeyEncrypterDecrypter role. Setting the flag alone will fail or result in an error because the prerequisite IAM permission is missing. The correct sequence is to create the KMS key and grant the role first, then run the gcloud create command with that flag.

About these practice questions

Courseiva writes every ACE question from scratch — 775 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Google Cloud exam blueprint

This ACE practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the ACE exam.