Courseiva
Google Cloud Security →easyMultiple Choice

Cloud Digital Leader Google Cloud Security Practice Question

An organization needs to ensure that data stored in Cloud Storage is encrypted using keys that they manage and rotate themselves. Which encryption option should they choose?

⚠ Common exam trap

GCDL often tests the confusion between CMEK and CSEK, where candidates might think CSEK offers more control, but the exam expects recognition that CMEK is for managed rotation within GCP.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Customer-managed encryption keys (CMEK)

Customer-managed encryption keys (CMEK) allow the organization to create, manage, and rotate encryption keys themselves using Cloud KMS, while still leveraging Google Cloud's encryption infrastructure. This meets the requirement for self-managed keys with rotation control. CMEK provides the necessary control without the operational burden of handling raw key material.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Customer-managed encryption keys (CMEK)

    Why this is correct

    CMEK lets you create and manage your own keys within Cloud KMS, giving you control over the full key lifecycle—rotation schedules, enables/disables, and deletions—while still leveraging Google's infrastructure for storage and encryption operations. You can grant and revoke access to keys via IAM, and audit key use with Cloud Audit Logs. This directly satisfies the need to manage keys as the customer, because you retain administrative authority over the key material that protects the data.

  • ✗

    Default encryption at rest

    Why it's wrong here

    Default encryption at rest automatically encrypts data using Google-managed keys before it is written to disk, with no action required from the customer. The keys are created and rotated behind the scenes, and the customer has no ability to view, manage, or control them. Because the organization specifically wants to manage keys itself rather than relying on Google's default transparency-free encryption, this option is incorrect.

  • ✗

    Customer-supplied encryption keys (CSEK)

    Why it's wrong here

    CSEK requires you to supply your own raw key material with every API call, and you must manage the key's lifecycle (generation, rotation, storage, and destruction) entirely outside Google. It does not integrate with Cloud KMS, so you forgo centralized key management, IAM-based access control for keys, and native rotation capabilities. This is why it does not meet the organization's need to manage keys through a managed service.

  • ✗

    Google-managed encryption keys

    Why it's wrong here

    Google-managed encryption keys are fully owned and operated by Google: Google generates, stores, rotates, and controls access to the keys, with no customer visibility or management capability. While this provides robust default security, it fails the requirement when an organization needs to exercise its own control, set key rotation policies, or define per-key IAM permissions. The org's requirement implies active customer governance over key material, which this option cannot deliver.

About these practice questions

This GCDL question is part of Courseiva's 848-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Google Cloud exam blueprint

This GCDL practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCDL exam.