Courseiva
Google Cloud SecurityeasyMultiple ChoiceObjective-mapped

Cloud Digital Leader Google Cloud Security Practice Question

An organization needs to ensure that data stored in Cloud Storage is encrypted using keys that they manage and rotate themselves. Which encryption option should they choose?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Customer-managed encryption keys (CMEK)

CMEK allows customers to manage their own keys via Cloud KMS. CSEK requires customer-supplied keys but has operational overhead. Google-managed keys are default but not customer-managed.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Customer-managed encryption keys (CMEK)

    Why this is correct

    CMEK lets you create and manage your own keys within Cloud KMS, giving you control over the full key lifecycle—rotation schedules, enables/disables, and deletions—while still leveraging Google's infrastructure for storage and encryption operations. You can grant and revoke access to keys via IAM, and audit key use with Cloud Audit Logs. This directly satisfies the need to manage keys as the customer, because you retain administrative authority over the key material that protects the data.

  • Default encryption at rest

    Why it's wrong here

    Default encryption at rest automatically encrypts data using Google-managed keys before it is written to disk, with no action required from the customer. The keys are created and rotated behind the scenes, and the customer has no ability to view, manage, or control them. Because the organization specifically wants to manage keys itself rather than relying on Google's default transparency-free encryption, this option is incorrect.

  • Customer-supplied encryption keys (CSEK)

    Why it's wrong here

    CSEK requires you to supply your own raw key material with every API call, and you must manage the key's lifecycle (generation, rotation, storage, and destruction) entirely outside Google. It does not integrate with Cloud KMS, so you forgo centralized key management, IAM-based access control for keys, and native rotation capabilities. This is why it does not meet the organization's need to manage keys through a managed service.

  • Google-managed encryption keys

    Why it's wrong here

    Google-managed encryption keys are fully owned and operated by Google: Google generates, stores, rotates, and controls access to the keys, with no customer visibility or management capability. While this provides robust default security, it fails the requirement when an organization needs to exercise its own control, set key rotation policies, or define per-key IAM permissions. The org's requirement implies active customer governance over key material, which this option cannot deliver.

About these practice questions

This GCDL question is part of Courseiva's 829-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This GCDL practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCDL exam.