Courseiva
Trust and security with Google CloudeasyMultiple ChoiceObjective-mapped

Cloud Digital Leader Trust and security with Google Cloud Practice Question

A company stores customer data in Google Cloud and wants to ensure data confidentiality in the event that hardware is decommissioned and returned by Google. How does Google protect customer data when storage hardware reaches end of life?

⚠ Common exam trap

A common mix-up: candidates assume encryption alone (Option C) is sufficient for decommissioned hardware, but Google's policy requires physical destruction or verified erasure to prevent data recovery from encrypted drives if keys are later compromised.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Google uses approved data erasure and physical destruction processes (shredding, degaussing) for decommissioned storage media before hardware leaves its facilities.

Google Cloud follows strict data destruction policies for decommissioned storage media. Before any hardware leaves Google's facilities, it undergoes approved data erasure (e.g., NIST SP 800-88 compliant wiping) followed by physical destruction (e.g., shredding, degaussing) to ensure customer data cannot be recovered. This process guarantees data confidentiality even if the hardware is returned or recycled.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Google transfers customer data to new hardware first, then ships the old hardware to the customer for self-destruction.

    Why it's wrong here

    Google never ships used storage media or servers to customers, nor does it require customers to self-destruct hardware. Customer data is logically migrated to other resources as part of normal operations, but physical hardware remains Google-owned and is decommissioned in accordance with Google's own security policies. Sending used hardware to customers would violate data isolation and compliance commitments, so this option reflects a fundamental misunderstanding of the shared responsibility model.

  • Google uses approved data erasure and physical destruction processes (shredding, degaussing) for decommissioned storage media before hardware leaves its facilities.

    Why this is correct

    This is the correct answer. Google follows NIST 800-88-compliant sanitization procedures for storage media, combining cryptographic erase (secure key destruction) with physical destruction methods such as shredding and degaussing. These steps are performed inside Google's data centers before any hardware leaves the premises, and the process is independently audited to verify effectiveness. This guarantees that customer data cannot be reconstructed from decommissioned media.

  • Customer data on decommissioned hardware is automatically encrypted, making it safe to discard without wiping.

    Why it's wrong here

    Encryption at rest protects data while drives remain in service, but it is not a substitute for sanitization during decommissioning. If the encryption keys are ever recovered or were escrowed, ciphertext becomes readable; also, failed or repurposed drives may contain plaintext remnants. Google's decommissioning process therefore includes verified cryptographic erasure followed by physical destruction of the media, ensuring data is unrecoverable even if the drive itself is discarded.

  • Customers must pay a data destruction fee to ensure their data is wiped from decommissioned hardware.

    Why it's wrong here

    Secure data destruction is a standard, built-in part of Google's cloud operations, not a paid add-on. Customers do not need to purchase a separate 'data destruction fee' because Google's service terms and compliance accreditations already cover verified sanitization of decommissioned storage media. Any implication of an extra cost misrepresents Google's contractual and operational commitment to data protection.

About these practice questions

This GCDL question is part of Courseiva's 829-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This GCDL practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCDL exam.