Cloud Digital Leader Trust and security with Google Cloud Practice Question
A company is concerned about which security responsibilities belong to Google versus which belong to them when using Google Cloud's managed database service (Cloud SQL). In the shared responsibility model, which security tasks does Google handle?
⚠ Common exam trap
Many exam-takers confuse Google's responsibility for patching the database software (which Google handles) with the customer's responsibility for managing database access controls and backup configurations, leading them to incorrectly select options A or C.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Google handles physical security, hardware maintenance, and OS and database software patching.
In the shared responsibility model for Google Cloud services like Cloud SQL, Google is responsible for security 'of' the cloud, which includes physical security of data centers, hardware maintenance, and patching the underlying operating system and database software. This ensures the infrastructure hosting Cloud SQL instances is secure, while the customer remains responsible for securing their data, access policies, and application-level configurations.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Google controls who can access the database and what data can be stored.
Why it's wrong here
In Google Cloud managed databases like Cloud SQL or AlloyDB, the customer creates database users, assigns IAM roles, manages SSL/TLS certificates, and defines schemas. Google never makes decisions about who can query a table or what columns or records exist. That access control and data governance responsibility rests with the database administrator at the customer's organization. Thus, this statement is incorrect because it inverts the shared responsibility model for data plane access.
- ✓
Google handles physical security, hardware maintenance, and OS and database software patching.
Why this is correct
This is the correct description of the shared responsibility model for managed database services like Cloud SQL. Google is responsible for data center physical security (e.g., biometric access controls, armed guards), hardware lifecycle management (failed disk replacement), and patching the underlying operating system and database engine. For example, Cloud SQL automatically applies minor version updates and security patches; customers can schedule maintenance windows for major upgrades. These infrastructure-level tasks are handled entirely by Google, which is what distinguishes a fully managed service from a self-managed Compute Engine VM.
- ✗
Google is responsible for backing up customer data and ensuring data recovery.
Why it's wrong here
In services like Cloud SQL, Google operates the backup infrastructure—automatically creating backups when enabled—but the decision to enable backups, set retention windows, and perform point-in-time recovery belongs to the customer. Customers must also test restore procedures and integrate backups into their overall disaster recovery plan. Google does not proactively ensure data recoverability unless the customer configures these features; if backups are disabled or deleted, Google typically cannot restore the data. Therefore, this responsibility is shared, not entirely Google's.
- ✗
Google determines which compliance certifications the customer's application must meet.
Why it's wrong here
Compliance obligations like PCI DSS, HIPAA, or GDPR apply based on the customer's business, data type, and jurisdiction, not on Google's choices. Google does not assess your application's requirements; instead, it offers a set of certifications and compliance reports (e.g., SOC 2, ISO 27001) that customers use as evidence of the infrastructure's controls. The customer is responsible for architecting the application and configuring GCP services to meet those regulatory standards. Google's role is to provide the secure foundation and compliance artifacts, not to decide what the customer must comply with.
Go deeper
Related to this question
Learn chapter
Cloud Digital Transformation
Key term
Shared responsibility
Shared responsibility is a cloud security model where the cloud provider and the customer each own distinct parts of security and compliance duties.
Key term
Service
A service is a software component or system that performs a specific function and is available to be used by other programs or users over a network.
About these practice questions
One of 829 original GCDL practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This GCDL practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCDL exam.