Cloud Digital Leader Fundamental Cloud Concepts Practice Question
A regional accounting firm is moving its document management system to Google Cloud. The firm's partners are concerned about where client financial records will physically reside and want assurance that the data stays within their country. They also want to understand who is responsible for securing the underlying physical data center versus the application configuration. Which statement accurately describes the Google Cloud shared responsibility model in this context?
⚠ Common exam trap
The trap here is believing that moving to the cloud transfers all security duties to the provider, when customers always remain responsible for their data and configuration.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Google is responsible for the security of the cloud, including physical data centers and hardware, while the firm is responsible for security in the cloud, including data and application configuration
The shared responsibility model divides duties: Google handles security of the cloud, meaning the physical facilities, hardware, and core infrastructure, while the customer handles security in the cloud, meaning data, identities, and application configuration. The firm retains control over client records and access settings, while relying on Google for data center safeguards and residency through region selection.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The firm is responsible for physical data center security because it retains ownership of the data, while Google only manages software updates
Why it's wrong here
Customers never manage Google's physical data centers; Google owns and operates those facilities and their physical controls. The firm's responsibility begins with the data and configurations it places in the cloud. Reversing these roles misstates the model and would lead the firm to attempt controls it cannot perform on Google's premises.
- ✗
Google is responsible for securing both the infrastructure and all customer data, so the firm does not need to configure access controls
Why it's wrong here
Google secures the underlying infrastructure but never assumes responsibility for customer data classification, access management, or application-level configuration. The firm must still configure IAM policies, encryption choices, and document permissions. Claiming otherwise would leave client financial records exposed through misconfigured access settings that Google does not manage.
- ✓
Google is responsible for the security of the cloud, including physical data centers and hardware, while the firm is responsible for security in the cloud, including data and application configuration
Why this is correct
Under the shared responsibility model, Google secures the infrastructure that runs all services, such as data centers, networking, and hardware, while the customer secures what it puts in the cloud, including data, access policies, and application settings. This division lets the firm focus on its document system configuration while relying on Google for physical safeguards.
- ✗
Responsibility is split evenly, with Google and the firm jointly configuring the hypervisor and guest operating system for every workload
Why it's wrong here
The split is not an even fifty-fifty arrangement, and it varies by service model. Google manages the hypervisor and physical layers, while the customer's responsibility for the guest operating system depends on whether the workload is IaaS, PaaS, or SaaS. Joint configuration of every layer is not how the model operates and would create ambiguous ownership.
Go deeper
Related to this question
Learn chapter
Google Cloud Infrastructure
Key term
Security
Security in IT is the practice of protecting systems, networks, and data from unauthorized access, damage, or theft.
Key term
Model
In IT and AI, a model is a trained mathematical representation that learns patterns from data to make predictions or decisions.
About these practice questions
This GCDL question is part of Courseiva's 848-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Google Cloud exam blueprint
This GCDL practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCDL exam.