Cloud Digital Leader Trust and security with Google Cloud Practice Question
A financial services company is subject to regulations requiring them to demonstrate that their cloud provider's employees cannot access customer data without the customer's explicit approval. Which Google Cloud feature most directly addresses this requirement?
⚠ Common exam trap
The GCDL exam often tests the distinction between encryption key control (CMEK) and access governance (Access Transparency/Approval), leading candidates to mistakenly choose CMEK because they conflate key management with personnel access control.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Access Transparency and Access Approval, which log and require explicit customer approval for Google personnel access to customer content
Access Transparency and Access Approval directly address the regulatory requirement by providing near real-time logs of Google personnel actions on customer content and requiring explicit customer approval before such access can occur. Access Transparency logs every access attempt by Google employees, while Access Approval allows customers to approve or deny those requests, ensuring no unauthorized access without customer consent.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Customer-Managed Encryption Keys (CMEK), where the customer controls the encryption key and can revoke access
Why it's wrong here
Customer-Managed Encryption Keys (CMEK) give the customer authority over the key material that encrypts their data at rest, and revoking the key can cryptographically render data unreadable, including to Google personnel. However, this is a technical access control that operates at the storage layer, not a governance mechanism that logs who accessed the data or why, and it doesn't require the customer to pre-approve each provider access request. It also does not support fine-grained oversight — there is no separate approval workflow for individual access incidents, only the binary act of key rotation or destruction.
- ✓
Access Transparency and Access Approval, which log and require explicit customer approval for Google personnel access to customer content
Why this is correct
Access Transparency logs all Google personnel access to customer content with justification codes. Access Approval requires Google to request explicit customer approval before accessing customer data. Together they directly address the regulatory requirement for customer oversight of provider access to their data.
- ✗
Cloud Audit Logs, which record all customer actions within Google Cloud
Why it's wrong here
Cloud Audit Logs provide a detailed record of operations performed by customers, end users, and service accounts, such as resource creations, modifications, and data-access events initiated within a GCP project. But they are scoped to activity under the customer's own cloud identity domain, and they do not capture manual access by Google Cloud employees to underlying customer data. That class of provider-side activity is opaque to Cloud Audit Logs and is specifically the gap that Access Transparency fills, making these logs an incomplete answer for this regulatory need.
- ✗
VPC Service Controls, which prevent Google employees from accessing resources inside the service perimeter
Why it's wrong here
VPC Service Controls create service perimeters that limit data exfiltration by restricting the network context of API calls, such as IP ranges or VPC sources. However, these perimeters enforce policies on the customer's data-plane traffic and do not govern the administrative sessions of Google Cloud's own support or engineering staff. They offer no audit trail of provider actions and no mechanism to require approval for Google personnel to access customer content, so they cannot satisfy an oversight requirement.
Go deeper
Related to this question
Learn chapter
Cloud Digital Transformation
Key term
Regulatory requirement
A regulatory requirement is a rule issued by a government or industry authority that organizations must follow, often to protect data, ensure safety, or maintain fair practices.
Key term
Data
Data is raw, unprocessed information, like numbers, words, or measurements, that can be stored, processed, and analyzed by computers.
About these practice questions
One of 829 original GCDL practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This GCDL practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCDL exam.