Courseiva
Why Cloud Technology Can Transform BusinessmediumMultiple ChoiceObjective-mapped

Cloud Digital Leader Why Cloud Technology Can Transform Business Practice Question

A healthcare startup is building a HIPAA-compliant application on Google Cloud. They need to encrypt data at rest and manage their own encryption keys. Which service should they use for key management?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Cloud Key Management Service (Cloud KMS)

Cloud KMS allows customers to manage their own encryption keys, and when used with CMEK, ensures data-at-rest encryption for HIPAA compliance.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Cloud IAM

    Why it's wrong here

    Cloud IAM provides fine-grained access control for Google Cloud resources, allowing you to define who (identity) has access (role) to what (resource) — but it does not generate, rotate, or destroy any encryption key material. To meet HIPAA requirements around key governance, you need a dedicated key management service that can create and manage the lifecycle of the keys used to encrypt stored PHI. While Cloud IAM roles are used to authorize key administrators, the key management itself is outside its scope.

  • Cloud Data Loss Prevention (DLP)

    Why it's wrong here

    Cloud Data Loss Prevention (DLP) is a data classification and de-identification service that scans for sensitive patterns such as health data and applies redaction, masking, or tokenization to protect that data at the field level. DLP does not manage encryption keys; when it needs to encrypt data, you must supply a key from an external system like Cloud KMS, but DLP itself cannot create or control the lifecycle of those keys. Thus, while DLP helps discover and protect PHI, it is not the service designed for managing the cryptographic keys that underpin encryption.

  • Cloud HSM

    Why it's wrong here

    Cloud HSM provides hardware-backed key storage but does not allow the customer to manage their own encryption keys in the sense of controlling key material lifecycle outside Google’s infrastructure; the correct service for customer-managed keys is Cloud KMS with a customer-managed encryption key (CMEK), which lets the customer create, rotate, and delete keys via Cloud KMS APIs. Cloud HSM is tempting because it offers FIPS 140-2 Level 3 validated hardware security modules for high-security workloads, and would be the correct choice if the requirement were to perform cryptographic operations within a tamper-resistant HSM boundary rather than to manage key material directly.

  • Cloud Key Management Service (Cloud KMS)

    Why this is correct

    Cloud Key Management Service (Cloud KMS) is the correct answer because it is Google Cloud's managed service for creating, rotating, and destroying customer-managed encryption keys (CMEK). The service provides a software-based key management tier suitable for HIPAA compliance, and it also integrates with Cloud HSM to offer hardware-backed keys if FIPS 140-2 Level 3 validation is required. Because you retain control over the key material lifecycle and can audit key usage, Cloud KMS meets the security and governance requirements of a HIPAA-compliant application.

About these practice questions

This GCDL question is part of Courseiva's 829-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This GCDL practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCDL exam.