Google ACE Deploying and Implementing a Cloud Solution Practice Question
A data engineering team wants to create a Cloud Storage bucket for storing sensitive analytics data. They require encryption at rest with customer-managed keys (CMEK) and want to restrict access to a specific service account. Which three steps are necessary?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Set the bucket's default encryption to use the KMS key
To use CMEK, you must create a Cloud KMS key ring and key, then configure the bucket to use that key. Access is controlled via IAM; granting the service account roles/storage.objectAdmin allows full object management. Note: The KMS key must be in the same region as the bucket.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Set the bucket's default encryption to use the KMS key
Why this is correct
Setting the bucket's default encryption to point at the KMS key is the step that activates customer-managed encryption for Cloud Storage. All objects uploaded after this change are automatically encrypted with the selected Cloud KMS key instead of Google-owned keys. Without this configuration, the key ring and key remain unused and the bucket continues using default encryption.
- ✗
Enable uniform bucket-level access
Why it's wrong here
Enabling uniform bucket-level access makes all permissions be controlled solely by IAM bucket-level policies, effectively disabling object-level ACLs. While this is a recommended hardening practice for simpler permission management, it is not required for CMEK or for a service account to access objects. The service account's access is determined by IAM roles like roles/storage.objectAdmin, which function independently of whether ACLs are uniform or fine-grained.
- ✓
Grant the service account roles/storage.objectAdmin on the bucket
Why this is correct
Granting roles/storage.objectAdmin to the service account on the bucket provides a comprehensive set of object-level permissions—read, write, list, and delete—without granting bucket configuration or KMS admin privileges. This is the appropriate IAM binding for a data engineering service account that needs to manage objects in the bucket. It works regardless of the bucket's encryption settings, as IAM and CMEK are independent layers of control.
- ✗
Create a service account and download its JSON key
Why it's wrong here
Creating a new service account and downloading its JSON key is unnecessary because the service account referenced in the scenario already exists and access is granted through IAM bindings, not key files. A JSON key is a credential used for authentication, and downloading one does not itself grant any bucket permissions. In fact, generating a new key would require also assigning the appropriate IAM role to that new account and would introduce additional credentials that need to be securely managed.
- ✓
Create a Cloud KMS key ring and key in the same region as the bucket
Why this is correct
Cloud KMS key rings and keys are regional resources, so a key created in one region cannot be used for CMEK on a bucket in a different region. Creating the key ring and key in the same region as the bucket is a prerequisite for setting the bucket's default encryption to that key. Without this alignment, the bucket will reject the KMS key reference and CMEK configuration will fail.
Go deeper
Related to this question
Learn chapter
VPC Service Controls
Key term
Region
A region is a distinct geographic location where a cloud provider operates multiple data centers that are connected by low-latency networks and provide cloud services.
Key term
Service account
A service account is a special type of account used by an application or a virtual machine, rather than a human user, to authenticate and interact with cloud services and APIs securely.
About these practice questions
This ACE question is part of Courseiva's 775-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This ACE practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the ACE exam.