Courseiva
Google Cloud Security →easyMultiple Choice

Cloud Digital Leader Google Cloud Security Practice Question

A small startup is migrating its web application to Google Cloud. The security lead wants to understand how Google protects the underlying infrastructure, including physical data centers, hardware, and the network, while the startup remains responsible for securing its own application code and data. Which security model describes this division of responsibilities?

⚠ Common exam trap

It's easy for candidates to confuse Zero Trust, a security design philosophy, with the shared responsibility model, which defines the provider-customer security boundary.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Shared responsibility model

Google Cloud operates on a shared responsibility model: Google is responsible for the security of the cloud, including physical facilities, hardware, and the network, while customers are responsible for security in the cloud, such as their data, applications, and identity configuration. This framework clarifies that the startup must secure its own code and access controls even though Google protects the underlying platform.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Least privilege model

    Why it's wrong here

    Least privilege is the practice of granting users only the minimum permissions needed to perform their tasks. It is an important IAM principle but does not explain how infrastructure security is divided between Google and the customer. The scenario asks about the overall security responsibility split, which is the shared responsibility model.

  • ✗

    Defense in depth model

    Why it's wrong here

    Defense in depth is a strategy of layering multiple security controls so that if one fails, others still protect the system. It is a useful principle but does not define the boundary between provider and customer duties. The startup's question is about responsibility allocation, which is answered by the shared responsibility model, not by defense in depth.

  • ✓

    Shared responsibility model

    Why this is correct

    In the shared responsibility model, Google secures the infrastructure—physical data centers, hardware, networking, and the hypervisor—while the customer secures what they put in the cloud, such as application code, data, and access management. This exactly matches the startup's need to understand which layers Google handles and which remain their own responsibility.

  • ✗

    Zero Trust security model

    Why it's wrong here

    Zero Trust is a design philosophy that assumes no implicit trust based on network location and requires continuous verification of every request. While Google applies Zero Trust principles internally, it does not describe the division of security responsibilities between Google and the customer. The shared responsibility model is the correct framework for understanding who secures what.

About these practice questions

One of 848 original GCDL practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Google Cloud exam blueprint

This GCDL practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCDL exam.