Cloud Digital Leader Google Cloud Security Practice Question
A small startup is migrating its web application to Google Cloud. The security lead wants to understand how Google protects the underlying infrastructure, including physical data centers, hardware, and the network, while the startup remains responsible for securing its own application code and data. Which security model describes this division of responsibilities?
⚠ Common exam trap
It's easy for candidates to confuse Zero Trust, a security design philosophy, with the shared responsibility model, which defines the provider-customer security boundary.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Shared responsibility model
Google Cloud operates on a shared responsibility model: Google is responsible for the security of the cloud, including physical facilities, hardware, and the network, while customers are responsible for security in the cloud, such as their data, applications, and identity configuration. This framework clarifies that the startup must secure its own code and access controls even though Google protects the underlying platform.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Least privilege model
Why it's wrong here
Least privilege is the practice of granting users only the minimum permissions needed to perform their tasks. It is an important IAM principle but does not explain how infrastructure security is divided between Google and the customer. The scenario asks about the overall security responsibility split, which is the shared responsibility model.
- ✗
Defense in depth model
Why it's wrong here
Defense in depth is a strategy of layering multiple security controls so that if one fails, others still protect the system. It is a useful principle but does not define the boundary between provider and customer duties. The startup's question is about responsibility allocation, which is answered by the shared responsibility model, not by defense in depth.
- ✓
Shared responsibility model
Why this is correct
In the shared responsibility model, Google secures the infrastructure—physical data centers, hardware, networking, and the hypervisor—while the customer secures what they put in the cloud, such as application code, data, and access management. This exactly matches the startup's need to understand which layers Google handles and which remain their own responsibility.
- ✗
Zero Trust security model
Why it's wrong here
Zero Trust is a design philosophy that assumes no implicit trust based on network location and requires continuous verification of every request. While Google applies Zero Trust principles internally, it does not describe the division of security responsibilities between Google and the customer. The shared responsibility model is the correct framework for understanding who secures what.
Go deeper
Related to this question
Learn chapter
Google Cloud Infrastructure
Key term
Google Cloud
Google Cloud is a suite of cloud computing services offered by Google that provides infrastructure, platform, and software solutions over the internet.
Key term
Shared responsibility
Shared responsibility is a cloud security model where the cloud provider and the customer each own distinct parts of security and compliance duties.
About these practice questions
One of 848 original GCDL practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Google Cloud exam blueprint
This GCDL practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCDL exam.