Cloud Digital Leader Trust and security with Google Cloud Practice Question
A company has migrated sensitive customer data to Google Cloud. The legal team asks: 'If Google is hosting our data, who is responsible for ensuring that data is not improperly accessed by unauthorized users through our application?' Under the shared responsibility model, how should the CTO answer?
⚠ Common exam trap
A common mix-up: candidates assume the cloud provider is fully responsible for all security aspects, but the shared responsibility model explicitly places application-layer access controls, authentication, and IAM on the customer, especially when the question specifies 'through our application'.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The customer is responsible for application access controls, authentication, and IAM policies that protect data from unauthorized application-layer access, while Google secures the underlying infrastructure
Under the Google Cloud shared responsibility model, the customer is responsible for securing access to their application and data, including authentication, authorization, and IAM policies, while Google is responsible for the security of the underlying infrastructure (physical security, network, hypervisor). The legal team's question specifically asks about unauthorized access through the customer's application, which falls under the customer's responsibility for application-layer controls.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Google is fully responsible because they host the data and control the infrastructure
Why it's wrong here
This option misreads the shared responsibility model by conflating infrastructure ownership with all security duties. Google does secure physical data centers, networking, and the hypervisor, but it does not manage who is authenticated to the customer's application or what IAM permissions are granted to service accounts. Weak authentication, over-privileged roles, and application-layer vulnerabilities are the customer's responsibility to control, so the customer cannot shift that liability to Google merely because their data resides in Google Cloud.
- ✓
The customer is responsible for application access controls, authentication, and IAM policies that protect data from unauthorized application-layer access, while Google secures the underlying infrastructure
Why this is correct
This is the correct shared responsibility answer. Google secures the infrastructure layer — physical hardware, network, hypervisor. The customer must secure their application layer: who can access the application, how they authenticate, what permissions their service accounts have, and whether the application has vulnerabilities.
- ✗
Both Google and the customer share equal 50/50 responsibility for all data access controls
Why it's wrong here
The shared responsibility model is not a percentage-based split; it is a layered division of duties. Google is responsible for the security of the cloud (physical hardware, host OS, hypervisor, and network), while the customer is responsible for security in the cloud (data classification, identity access management, application configuration, and patch management). A 50/50 allocation fails to recognize that for most data access controls, such as IAM policies and user authentication, the customer has full ownership and sole authority, so responsibility is not evenly shared across every control.
- ✗
No one is responsible because cloud computing inherently cannot prevent unauthorized access
Why it's wrong here
This claim is false because cloud providers and customers can and do prevent unauthorized access through well-established mechanisms like IAM policies, multi-factor authentication, least-privilege roles, and data encryption. The shared responsibility model exists precisely because both parties have enforceable, clearly defined security obligations; cloud infrastructure is not inherently insecure. Additionally, regulatory frameworks such as SOC 2, ISO 27017, and PCI DSS require these controls to be implemented, proving that unauthorized access prevention is not only possible but expected in cloud environments.
Go deeper
Related to this question
Learn chapter
Cloud Digital Transformation
Key term
IAM
Identity and Access Management (IAM) is a framework of policies and technologies that ensures the right individuals have the appropriate access to technology resources.
Key term
Security
Security in IT is the practice of protecting systems, networks, and data from unauthorized access, damage, or theft.
About these practice questions
Courseiva writes every GCDL question from scratch — 829 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This GCDL practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCDL exam.