Cloud Digital Leader Trust and security with Google Cloud Practice Question
A security architect is evaluating Google Cloud's approach to securing customer data against both external attackers and potential internal Google personnel access. She identifies four distinct controls: (1) encryption at rest by default, (2) Access Transparency logs, (3) Customer-Managed Encryption Keys (CMEK), and (4) Access Approval. How do these four controls work together to provide layered data protection?
⚠ Common exam trap
Google Cloud often tests the misconception that encryption alone is sufficient for data protection, ignoring the need for access transparency and approval mechanisms to address insider threats and provider access concerns.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The four controls form complementary layers: default encryption protects physical storage, CMEK gives cryptographic customer control (revocable), Access Transparency provides visibility into Google personnel access, and Access Approval gives customers veto power — together addressing infrastructure attacks, insider threats, and provider access concerns
These four controls form a defense-in-depth strategy for data protection on Google Cloud. Default encryption at rest secures data on physical storage, CMEK provides cryptographic control with the ability to revoke access, Access Transparency logs offer visibility into Google personnel actions, and Access Approval gives customers the ability to veto access requests. Together, they address threats from infrastructure attacks, insider threats, and provider access concerns, creating a layered security model.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
All four controls are redundant and address the same threat — customers only need to enable one of them
Why it's wrong here
The four controls are not redundant; each addresses a distinct part of the data protection problem. Default encryption at rest protects against physical media theft, while CMEK gives the customer independent cryptographic control over the key, allowing them to revoke Google's ability to decrypt data. Access Transparency provides an auditable trail of Google personnel actions, and Access Approval requires explicit customer sign-off before those actions can occur. If a customer enables only CMEK, they still lack visibility into provider operations and the ability to pre-authorize access; enabling only Access Transparency gives audit logs but no cryptographic separation or veto capability. Thus, the controls are complementary and must be used together for full defense-in-depth.
- ✓
The four controls form complementary layers: default encryption protects physical storage, CMEK gives cryptographic customer control (revocable), Access Transparency provides visibility into Google personnel access, and Access Approval gives customers veto power — together addressing infrastructure attacks, insider threats, and provider access concerns
Why this is correct
This correctly describes the layered defense. Default encryption: protects against physical media theft. CMEK: customer controls the key — can cryptographically revoke Google's ability to decrypt. Access Transparency: audit trail of provider access. Access Approval: proactive veto before access. Together they provide defense at every layer of the provider access concern.
- ✗
These controls are only relevant for government or military workloads; commercial enterprises don't need this level of protection
Why it's wrong here
This control set is not restricted to government or military use; it is available to all Google Cloud customers and is widely adopted by commercial enterprises in healthcare, finance, and retail that handle sensitive personal data. Compliance frameworks such as HIPAA, PCI-DSS, and SOC 2 often mandate or strongly suggest audit logging and customer-managed encryption keys, and insider threats are a concern for every organization, not only public-sector entities. Access Transparency logs and Access Approval workflows are standard features that any enterprise can enable to meet their own security and compliance requirements, so saying they are irrelevant to commercial workloads mischaracterizes both the threat model and Google Cloud's product offerings.
- ✗
CMEK alone provides complete data protection — the other three controls are unnecessary if customer-managed keys are in use
Why it's wrong here
CMEK provides cryptographic control but doesn't provide visibility (Access Transparency), require pre-approval of access (Access Approval), or protect unencrypted data-in-transit through Google's infrastructure (default at-rest encryption addresses a different concern). Each control fills a different gap.
Go deeper
Related to this question
Learn chapter
Cloud Digital Transformation
Key term
Data
Data is raw, unprocessed information, like numbers, words, or measurements, that can be stored, processed, and analyzed by computers.
Key term
Transparency
Transparency in AI means that the inner workings, decision-making processes, and data used by an AI system are open, understandable, and auditable by humans.
About these practice questions
One of 829 original GCDL practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This GCDL practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCDL exam.