Courseiva
Trust and security with Google CloudmediumMultiple ChoiceObjective-mapped

Cloud Digital Leader Trust and security with Google Cloud Practice Question

A financial services company is subject to regulations requiring them to demonstrate that their cloud provider's employees cannot access customer data without the customer's explicit approval. Which Google Cloud feature most directly addresses this requirement?

⚠ Common exam trap

The GCDL exam often tests the distinction between encryption key control (CMEK) and access governance (Access Transparency/Approval), leading candidates to mistakenly choose CMEK because they conflate key management with personnel access control.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Access Transparency and Access Approval, which log and require explicit customer approval for Google personnel access to customer content

Access Transparency and Access Approval directly address the regulatory requirement by providing near real-time logs of Google personnel actions on customer content and requiring explicit customer approval before such access can occur. Access Transparency logs every access attempt by Google employees, while Access Approval allows customers to approve or deny those requests, ensuring no unauthorized access without customer consent.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Customer-Managed Encryption Keys (CMEK), where the customer controls the encryption key and can revoke access

    Why it's wrong here

    Customer-Managed Encryption Keys (CMEK) give the customer authority over the key material that encrypts their data at rest, and revoking the key can cryptographically render data unreadable, including to Google personnel. However, this is a technical access control that operates at the storage layer, not a governance mechanism that logs who accessed the data or why, and it doesn't require the customer to pre-approve each provider access request. It also does not support fine-grained oversight — there is no separate approval workflow for individual access incidents, only the binary act of key rotation or destruction.

  • Access Transparency and Access Approval, which log and require explicit customer approval for Google personnel access to customer content

    Why this is correct

    Access Transparency logs all Google personnel access to customer content with justification codes. Access Approval requires Google to request explicit customer approval before accessing customer data. Together they directly address the regulatory requirement for customer oversight of provider access to their data.

  • Cloud Audit Logs, which record all customer actions within Google Cloud

    Why it's wrong here

    Cloud Audit Logs provide a detailed record of operations performed by customers, end users, and service accounts, such as resource creations, modifications, and data-access events initiated within a GCP project. But they are scoped to activity under the customer's own cloud identity domain, and they do not capture manual access by Google Cloud employees to underlying customer data. That class of provider-side activity is opaque to Cloud Audit Logs and is specifically the gap that Access Transparency fills, making these logs an incomplete answer for this regulatory need.

  • VPC Service Controls, which prevent Google employees from accessing resources inside the service perimeter

    Why it's wrong here

    VPC Service Controls create service perimeters that limit data exfiltration by restricting the network context of API calls, such as IP ranges or VPC sources. However, these perimeters enforce policies on the customer's data-plane traffic and do not govern the administrative sessions of Google Cloud's own support or engineering staff. They offer no audit trail of provider actions and no mechanism to require approval for Google personnel to access customer content, so they cannot satisfy an oversight requirement.

About these practice questions

One of 829 original GCDL practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This GCDL practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCDL exam.