Cloud Digital Leader Fundamental Cloud Concepts Practice Question
According to the shared responsibility model, which of the following is the customer responsible for?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Data encryption and access control (IAM)
Customers are responsible for securing their data, applications, and identity (IAM). Google is responsible for physical infrastructure, networks, and hypervisor security.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Physical security of data centers
Why it's wrong here
Physical data center security, including badge access, biometric authentication, and on-site guards, is a foundational component of the 'security of the cloud' that Google maintains exclusively. Customers have no physical presence in Google data centers and therefore cannot influence or alter these controls. Because the question asks for a customer-managed control, this option is incorrect.
- ✗
Network infrastructure security
Why it's wrong here
Network infrastructure security encompasses the entire Google backbone, border gateways, and software-defined networking controllers that route traffic between regions and zones. Google implements DDoS protection, intrusion detection, and encrypted traffic between data centers at a depth that the customer never touches. While customers secure their own VPC configurations, they do not manage the underlying network fabric, making this option incorrect.
- ✓
Data encryption and access control (IAM)
Why this is correct
Customers retain responsibility for encrypting their data both at rest and in transit, as well as for defining and enforcing access control through IAM policies. This includes managing encryption keys (via Cloud KMS or customer-supplied keys), configuring identity and role-based access, and applying organizational policies. Since these are direct customer actions within the cloud console and APIs, this is the correct choice.
- ✗
Hypervisor security
Why it's wrong here
Hypervisor security is a tight control plane that isolates virtual machines from each other and from the host, and it is entirely owned by Google as part of the compute infrastructure. Customers interact with virtualized resources but never have visibility into or management of the hypervisor layer. This separation is critical for multi-tenancy, and the customer has no responsibility for its maintenance, so the option is incorrect.
Go deeper
Related to this question
Learn chapter
Benefits of Google Cloud
Key term
Hypervisor
A hypervisor is software that creates and runs virtual machines by allowing multiple operating systems to share a single hardware host.
Key term
Model
In IT and AI, a model is a trained mathematical representation that learns patterns from data to make predictions or decisions.
About these practice questions
This GCDL question is part of Courseiva's 829-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This GCDL practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCDL exam.