Cloud Digital Leader Google Cloud Security Practice Question
A company wants to store encryption keys for encrypting data at rest in Cloud Storage, and also needs to automatically rotate the keys every 30 days. Additionally, they require an audit log of key usage. Which TWO services should they use? (Choose two.)
⚠ Common exam trap
GCDL often tests whether candidates confuse Secret Manager (secrets) with Cloud KMS (encryption keys) and whether they realize Cloud HSM is a key-protection level inside KMS rather than a standalone service that also provides audit logs.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Cloud KMS
Cloud KMS (C) is correct because it is the Google Cloud service designed to create and manage cryptographic keys used for encrypting data at rest, including Cloud Storage objects via customer-managed encryption keys (CMEK), and it natively supports automatic key rotation schedules (e.g., every 30 days) through rotation periods on key versions. Cloud Audit Logs (D) is correct because it records administrative and data-access activity on Cloud KMS keys, such as Encrypt/Decrypt operations and key rotation events, providing the required audit trail of key usage. Cloud HSM (A) is not the right choice here because it is a hardware security module backing for Cloud KMS keys, not a separate service that provides rotation scheduling or audit logging by itself. Secret Manager (B) stores secrets like passwords and API keys, not encryption keys for data-at-rest encryption with rotation. Cloud Storage (E) is the data store being encrypted, not a key management or auditing service.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Cloud HSM
Why it's wrong here
Cloud HSM is a hardware security module service that operates as an extension of Cloud KMS, providing tamper-resistant hardware protection for cryptographic keys. However, it is not a standalone key management solution; it still requires Cloud KMS to handle key lifecycle, rotation, and IAM policies. Thus, for a company storing encryption keys for data encryption, Cloud KMS remains the necessary central service, and Cloud HSM alone would not suffice.
- ✗
Secret Manager
Why it's wrong here
Secret Manager is designed to store secrets such as API keys, passwords, and certificates, and it excels at securely managing access to those secrets within applications. Encryption keys, however, require cryptographic operations, versioning, and rotation policies that Secret Manager does not natively support. While it can technically hold key material, it lacks the key management features of Cloud KMS, making it an incorrect choice for storing encryption keys intended for encryption.
- ✓
Cloud KMS
Why this is correct
Cloud KMS is the correct choice because it is the Google Cloud service purpose-built for creating, storing, and managing encryption keys. It supports symmetric and asymmetric keys, automatic rotation, and fine-grained IAM controls, and it integrates with Cloud Storage, BigQuery, Compute Engine, and other services for seamless data encryption. Keys are kept in a centralized, secure environment, and you can use them to encrypt and decrypt data without exposing the raw key material.
- ✓
Cloud Audit Logs
Why this is correct
Cloud Audit Logs is correct as a complement to Cloud KMS because it records a detailed, immutable audit trail of all key operations, including generation, rotation, decryption attempts, and administrative actions. This logging is essential for compliance frameworks like HIPAA and PCI-DSS, which require evidence of key access and monitoring. Although Cloud Audit Logs does not store the encryption keys themselves, it is a vital service to include in a comprehensive encryption key management solution for governance and auditability.
- ✗
Cloud Storage
Why it's wrong here
Cloud Storage is an object storage service for storing arbitrary data at scale, but it is not optimized for managing encryption keys. Placing keys in a Cloud Storage bucket would not provide key rotation, versioning, or cryptographic integration with other services, and it would also expose raw key material to anyone with bucket access. For proper key lifecycle management and secure encryption, Cloud KMS is the appropriate service, not Cloud Storage.
Go deeper
Related to this question
Learn chapter
Observability: Logging, Monitoring, and Tracing
Key term
Audit trail
An audit trail is a chronological record of events, changes, or activities in a system that provides evidence of who did what, when, and from where.
Key term
Audit
An audit is a systematic, independent review of IT systems, processes, and controls to verify compliance with policies, standards, and regulations.
About these practice questions
Courseiva writes every GCDL question from scratch — 848 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Google Cloud exam blueprint
This GCDL practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCDL exam.