Courseiva
Fundamental Cloud ConceptshardMultiple ChoiceObjective-mapped

Cloud Digital Leader Fundamental Cloud Concepts Practice Question

A financial services company must store and process sensitive customer data that is subject to GDPR and PCI DSS. They need to ensure that data is encrypted at rest and in transit, and that encryption keys are managed by a hardware security module (HSM) that is FIPS 140-2 Level 3 certified. Which Google Cloud service should they use for key management?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Cloud Hardware Security Module (Cloud HSM)

Cloud HSM provides dedicated HSM hardware, FIPS 140-2 Level 3 certification, and allows customers to manage their own keys. Cloud KMS is software-based and only offers Level 1 validation. Cloud EKM uses external key management but the question asks for a Google-managed HSM option. Secret Manager is for storing secrets, not key management with HSM.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Cloud Hardware Security Module (Cloud HSM)

    Why this is correct

    Cloud HSM provides a cloud-based hardware security module that holds your encryption keys in tamper-resistant hardware, validated to FIPS 140-2 Level 3. It integrates with Cloud KMS, so you can generate, store, and use keys inside the HSM while retaining customer-managed control. This dedicated HSM meets the strict hardware protection required for sensitive financial services data, making it the correct choice.

  • Cloud External Key Manager (Cloud EKM)

    Why it's wrong here

    Cloud External Key Manager (Cloud EKM) lets you manage encryption keys in an external key management system, such as an on-premises appliance, while Google Cloud accesses them through a proxy. Because the keys reside outside Google's infrastructure, they are not stored in Google's HSM and are not protected by FIPS 140-2 Level 3 hardware. This fails the requirement for HSM-backed key management, so it is not the right answer.

  • Secret Manager

    Why it's wrong here

    Secret Manager is a service for storing and retrieving secrets like API keys, passwords, and certificates, not for managing encryption keys in hardware. It does not use HSMs or offer FIPS 140-2 Level 3 validation for key storage. Therefore, while it is useful for credential storage, it cannot meet the financial company's need for HSM-backed key management.

  • Cloud Key Management Service (Cloud KMS)

    Why it's wrong here

    Cloud KMS provides centralized key management and encryption operations, but its keys are protected in software at FIPS 140-2 Level 1. It lacks the dedicated HSM hardware required for Level 3 compliance. Even though Cloud KMS can be used to manage keys, this option does not fulfill the specific hardware security requirement, making it incorrect.

About these practice questions

This GCDL question is part of Courseiva's 829-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This GCDL practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCDL exam.