Courseiva

Google ACE Deploying and Implementing a Cloud Solution Practice Question

A data engineering team wants to create a Cloud Storage bucket for storing sensitive analytics data. They require encryption at rest with customer-managed keys (CMEK) and want to restrict access to a specific service account. Which three steps are necessary?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Set the bucket's default encryption to use the KMS key

To use CMEK, you must create a Cloud KMS key ring and key, then configure the bucket to use that key. Access is controlled via IAM; granting the service account roles/storage.objectAdmin allows full object management. Note: The KMS key must be in the same region as the bucket.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Set the bucket's default encryption to use the KMS key

    Why this is correct

    Setting the bucket's default encryption to point at the KMS key is the step that activates customer-managed encryption for Cloud Storage. All objects uploaded after this change are automatically encrypted with the selected Cloud KMS key instead of Google-owned keys. Without this configuration, the key ring and key remain unused and the bucket continues using default encryption.

  • ✗

    Enable uniform bucket-level access

    Why it's wrong here

    Enabling uniform bucket-level access makes all permissions be controlled solely by IAM bucket-level policies, effectively disabling object-level ACLs. While this is a recommended hardening practice for simpler permission management, it is not required for CMEK or for a service account to access objects. The service account's access is determined by IAM roles like roles/storage.objectAdmin, which function independently of whether ACLs are uniform or fine-grained.

  • ✓

    Grant the service account roles/storage.objectAdmin on the bucket

    Why this is correct

    Granting roles/storage.objectAdmin to the service account on the bucket provides a comprehensive set of object-level permissions—read, write, list, and delete—without granting bucket configuration or KMS admin privileges. This is the appropriate IAM binding for a data engineering service account that needs to manage objects in the bucket. It works regardless of the bucket's encryption settings, as IAM and CMEK are independent layers of control.

  • ✗

    Create a service account and download its JSON key

    Why it's wrong here

    Creating a new service account and downloading its JSON key is unnecessary because the service account referenced in the scenario already exists and access is granted through IAM bindings, not key files. A JSON key is a credential used for authentication, and downloading one does not itself grant any bucket permissions. In fact, generating a new key would require also assigning the appropriate IAM role to that new account and would introduce additional credentials that need to be securely managed.

  • ✓

    Create a Cloud KMS key ring and key in the same region as the bucket

    Why this is correct

    Cloud KMS key rings and keys are regional resources, so a key created in one region cannot be used for CMEK on a bucket in a different region. Creating the key ring and key in the same region as the bucket is a prerequisite for setting the bucket's default encryption to that key. Without this alignment, the bucket will reject the KMS key reference and CMEK configuration will fail.

About these practice questions

This ACE question is part of Courseiva's 775-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This ACE practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the ACE exam.