Courseiva

Cloud Digital Leader Trust and security with Google Cloud Practice Question

Which TWO actions are the customer's responsibility under the GCP shared responsibility model?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Managing user accounts and authentication

Under the GCP shared responsibility model, the customer is responsible for managing their own user accounts and authentication (Option A), since identity lifecycle, credential management, and authentication configuration for their users fall on the customer side of the line. The customer is also responsible for configuring IAM policies to control access (Option C), because defining who can do what on which resources via roles and bindings is a customer-controlled security task. By contrast, encryption of data at rest by default (Option B) is provided by Google as part of the platform's baseline security, network infrastructure maintenance (Option D) is handled by Google, and physical security of data centers (Option E) is entirely Google's responsibility.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Managing user accounts and authentication

    Why this is correct

    Managing user accounts and authentication sits with the customer because Google Cloud's shared responsibility model assigns identity management to the tenant, not the provider. Google secures the underlying infrastructure, but configuring users, credentials and access controls remains the customer's duty, satisfying the stem's requirement for a customer-owned action.

  • ✗

    Encryption of data at rest by default

    Why it's wrong here

    GCP encrypts data at rest by default across its storage services, so the customer configures nothing here; this is a Google-managed control. It tempts because customer-managed encryption keys (CMEK) are a customer task, but default encryption itself is not.

  • ✓

    Configuring IAM policies to control access

    Why this is correct

    Configuring IAM policies sits with the customer because Google Cloud operates on a shared responsibility model: Google secures the infrastructure, while the customer controls identity and access decisions for their own projects, resources and data.

  • ✗

    Network infrastructure maintenance

    Why it's wrong here

    Google maintains the underlying network fabric, routers and links; the customer only configures VPCs, firewall rules and routes. It tempts because customers do manage their own VPC topology, but maintaining Google's physical network infrastructure remains Google's responsibility.

  • ✗

    Physical security of data centers

    Why it's wrong here

    Google owns and operates the physical data centres, so guards, biometric access and hardware security sit with Google, not the customer. It tempts because on-premises or colocation deployments make physical security the customer's job, but that model does not apply here.

About these practice questions

One of 848 original GCDL practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This GCDL practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCDL exam.