Cloud Digital Leader Trust and security with Google Cloud Practice Question
A company is moving its financial reporting application to Google Cloud. The CFO asks: 'If Google Cloud experiences a data breach and our financial data is exposed, who is financially liable?' How should the cloud architect answer this question?
⚠ Common exam trap
Many exam-takers assume Google Cloud automatically assumes all liability for any data breach, ignoring the Shared Responsibility Model’s clear division of accountability based on the breach’s origin (infrastructure vs. customer-managed layers).
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Liability depends on where the breach originated: Google is responsible for failures in its infrastructure security; the customer is responsible for breaches resulting from misconfiguration, application vulnerabilities, or inadequate access controls in areas under their responsibility
The Google Cloud Shared Responsibility Model explicitly delineates liability: Google is responsible for the security of the cloud (e.g., physical infrastructure, hypervisor, network controls), while the customer is responsible for security in the cloud (e.g., IAM policies, application code, data encryption). In a breach, liability is determined by where the failure occurred—if Google’s infrastructure (e.g., GKE node isolation) fails, Google bears liability; if the customer misconfigures a Cloud Storage bucket or leaves a Compute Engine firewall open, the customer bears liability. This aligns with the CFO’s question about financial liability, which is not absolute but contingent on the breach’s origin.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Google Cloud bears full financial liability for all data breaches involving customer data on its platform
Why it's wrong here
This option is incorrect because Google Cloud's terms of service and the shared responsibility model expressly limit Google's liability to failures within its controlled domain (physical data center security, hypervisor integrity, and managed infrastructure services). Although Google indemnifies certain types of infrastructure-related breaches, the contractual liability caps and exclusions mean the customer retains financial responsibility for breaches originating from customer-managed resources, such as misconfigured IAM policies, unpatched VMs, or insecure application code. Thus, Google does not bear full financial liability; liability is apportioned based on which party controls the layer where the failure occurred.
- ✓
Liability depends on where the breach originated: Google is responsible for failures in its infrastructure security; the customer is responsible for breaches resulting from misconfiguration, application vulnerabilities, or inadequate access controls in areas under their responsibility
Why this is correct
This accurately describes the shared responsibility reality. If Google's physical security or hypervisor is breached, Google bears responsibility. If a misconfigured IAM policy exposes data (customer responsibility), the customer bears the consequences. The customer should also have cyber insurance to manage residual risk.
- ✗
The customer bears all liability for any breach because they chose to use cloud services
Why it's wrong here
This option is overly broad and contradicts the shared responsibility model, under which cloud providers accept contractual liability for security failures in their domain. For example, if Google's data center physical security or hypervisor isolation is compromised, Google would be liable for the resulting breach, not the customer. The customer's liability is not absolute merely because they chose cloud services; it only extends to the resources and configurations under their responsibility, such as identity management, network controls, and server-side encryption implementations. Therefore, a blanket customer liability clause is not supported by standard cloud agreements.
- ✗
No party is liable because data breaches in cloud are force majeure events similar to natural disasters
Why it's wrong here
This option is incorrect because data breaches are not force majeure events comparable to natural disasters; they are foreseeable risks that both parties manage through explicit security obligations. In cloud contracts, Google accepts liability for certain events (e.g., infrastructure defects) and the customer accepts liability for others (e.g., credential misuse), with service credits and indemnification clauses defining the consequences. Unlike earthquakes or floods, a breach is typically caused by a definable failure of one party's security controls, and liability flows from that failure rather than being excused as an act of God.
Go deeper
Related to this question
Learn chapter
Cloud Digital Transformation
Key term
Google Cloud
Google Cloud is a suite of cloud computing services offered by Google that provides infrastructure, platform, and software solutions over the internet.
Key term
Shared responsibility
Shared responsibility is a cloud security model where the cloud provider and the customer each own distinct parts of security and compliance duties.
About these practice questions
One of 829 original GCDL practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This GCDL practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCDL exam.