Cloud Digital Leader Why Cloud Technology Can Transform Business Practice Question
A company is moving a sensitive database to Cloud SQL. They need to encrypt data at rest using customer-managed encryption keys (CMEK) and rotate the key every 30 days. How should they set this up?
⚠ Common exam trap
The trap is confusing default encryption with CMEK and manual rotation with automatic rotation — candidates may pick enabling default encryption or manual rotation, but the requirement specifies customer-managed keys with automated 30-day rotation.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create a key in Cloud KMS, specify it as the CMEK for Cloud SQL, and set rotation period to 30 days
To use CMEK with Cloud SQL, you create a key in Cloud KMS, grant the Cloud SQL service account access, and specify that key as the CMEK for the instance. Setting the key's rotation period to 30 days automates rotation, meeting the requirement without manual intervention. This is the standard, supported configuration.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Enable encryption by default in Cloud SQL settings
Why it's wrong here
Cloud SQL always encrypts data at rest by default, but the built-in default encryption uses Google-managed keys, which do not give the customer control over key lifecycle or rotation. Enabling this setting alone would not satisfy a requirement for a customer-managed encryption key (CMEK), so it cannot meet the stated need.
- ✗
Use Cloud HSM to generate a key and import it to Cloud SQL
Why it's wrong here
Cloud HSM provides FIPS 140-2 level 3 validated hardware protection for keys, but Cloud SQL expects the key to be created and managed in Cloud KMS, with Cloud HSM as the protection level. Merely generating a key in HSM and 'importing' it to Cloud SQL is not a supported flow, and the option does not configure the required 30-day rotation, so it is incomplete.
- ✗
Create a key in Cloud KMS and manually rotate it each month
Why it's wrong here
Creating a key in Cloud KMS is a necessary step, but the requirement specifies an automatic 30-day rotation period. Manual rotation each month relies on an operator and is prone to missed rotations or compliance gaps, and the key also needs to be explicitly assigned as the CMEK for the Cloud SQL instance to take effect.
- ✓
Create a key in Cloud KMS, specify it as the CMEK for Cloud SQL, and set rotation period to 30 days
Why this is correct
This is the correct configuration: create a key in Cloud KMS, designate it as the customer-managed encryption key (CMEK) for the Cloud SQL instance, and set the rotation period to 30 days. Cloud KMS then automatically rotates the key material every 30 days, and Cloud SQL transparently re-encrypts data with the new key version, meeting the company's compliance requirement without manual intervention.
Go deeper
Related to this question
Learn chapter
Building a Data-Driven Culture
Key term
SQL
SQL is a standardized programming language used to manage and manipulate relational databases, enabling querying, updating, and data retrieval.
Key term
Encryption
Encryption is the process of converting readable data into a secret code to prevent unauthorized access.
About these practice questions
Courseiva writes every GCDL question from scratch — 848 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Google Cloud exam blueprint
This GCDL practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCDL exam.