Cloud Digital Leader Trust and security with Google Cloud Practice Question
Which TWO actions are the customer's responsibility under the GCP shared responsibility model?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Managing user accounts and authentication
Under the GCP shared responsibility model, the customer is responsible for managing their own user accounts and authentication (Option A), since identity lifecycle, credential management, and authentication configuration for their users fall on the customer side of the line. The customer is also responsible for configuring IAM policies to control access (Option C), because defining who can do what on which resources via roles and bindings is a customer-controlled security task. By contrast, encryption of data at rest by default (Option B) is provided by Google as part of the platform's baseline security, network infrastructure maintenance (Option D) is handled by Google, and physical security of data centers (Option E) is entirely Google's responsibility.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Managing user accounts and authentication
Why this is correct
Managing user accounts and authentication sits with the customer because Google Cloud's shared responsibility model assigns identity management to the tenant, not the provider. Google secures the underlying infrastructure, but configuring users, credentials and access controls remains the customer's duty, satisfying the stem's requirement for a customer-owned action.
- ✗
Encryption of data at rest by default
Why it's wrong here
GCP encrypts data at rest by default across its storage services, so the customer configures nothing here; this is a Google-managed control. It tempts because customer-managed encryption keys (CMEK) are a customer task, but default encryption itself is not.
- ✓
Configuring IAM policies to control access
Why this is correct
Configuring IAM policies sits with the customer because Google Cloud operates on a shared responsibility model: Google secures the infrastructure, while the customer controls identity and access decisions for their own projects, resources and data.
- ✗
Network infrastructure maintenance
Why it's wrong here
Google maintains the underlying network fabric, routers and links; the customer only configures VPCs, firewall rules and routes. It tempts because customers do manage their own VPC topology, but maintaining Google's physical network infrastructure remains Google's responsibility.
- ✗
Physical security of data centers
Why it's wrong here
Google owns and operates the physical data centres, so guards, biometric access and hardware security sit with Google, not the customer. It tempts because on-premises or colocation deployments make physical security the customer's job, but that model does not apply here.
Go deeper
Related to this question
Learn chapter
Looker Studio (Data Studio) for Visualisation
Key term
Data
Data is raw, unprocessed information, like numbers, words, or measurements, that can be stored, processed, and analyzed by computers.
Key term
Shared responsibility
Shared responsibility is a cloud security model where the cloud provider and the customer each own distinct parts of security and compliance duties.
About these practice questions
One of 848 original GCDL practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This GCDL practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCDL exam.