Courseiva
Fundamental Cloud ConceptsmediumMultiple ChoiceObjective-mapped

Cloud Digital Leader Fundamental Cloud Concepts Practice Question

A company wants to use Google Cloud for a workload that requires compliance with PCI DSS. Which of the following is a Google responsibility under the shared model?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Patching the hypervisor

Google is responsible for maintaining the security of the infrastructure, including the hypervisor, network, and physical security, which are part of PCI DSS compliance scope for the cloud provider.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Configuring firewall rules to protect cardholder data

    Why it's wrong here

    Configuring firewall rules to protect cardholder data is a customer responsibility because firewall policies operate at the virtual network level where customers define allowed traffic and access controls. Under the shared responsibility model, Google manages the physical network and hypervisor, but the customer must design and implement VPC firewall rules to restrict exposure of sensitive data. Therefore, any failure to protect data via firewalls is attributed to customer misconfiguration, not Google's infrastructure.

  • Managing access keys for cardholder data

    Why it's wrong here

    Managing access keys for cardholder data falls squarely on the customer because identity and access management (IAM) decisions, including creating, rotating, and revoking keys, are customer-controlled functions within their projects. Google's responsibilities are limited to the underlying cloud infrastructure, not the credentials that grant access to data stored on that infrastructure. Even though Google provides IAM services, the customer is accountable for configuring and using them correctly to protect data.

  • Encrypting cardholder data at rest

    Why it's wrong here

    Encrypting cardholder data at rest is the customer's obligation because while Google encrypts all data by default, customer-controlled key management (such as CMEK or CSEK) and the decision to enable encryption are under the customer's authority. The shared responsibility model explicitly places data classification, encryption, and key protection on the customer, since Google cannot know the sensitivity of the data. Thus, a data breach due to weak encryption choices would be the customer's fault, not a failure of Google's infrastructure.

  • Patching the hypervisor

    Why this is correct

    Patching the hypervisor is a Google responsibility because the hypervisor is a core component of the infrastructure that hosts all customer virtual machines and is fully managed by Google. Google performs security patches and updates to the hypervisor without customer involvement, ensuring that vulnerabilities in the virtualization layer are addressed. This is a clear example of where the cloud provider, not the customer, maintains the security of the foundational compute environment.

About these practice questions

One of 829 original GCDL practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This GCDL practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCDL exam.