Google PCA Design for security and compliance Practice Question
A company needs to ensure that all data stored in Cloud Storage is encrypted at rest with keys that they control and can rotate on demand. They also need to maintain an audit trail of key usage. Which Google Cloud service should they use?
⚠ Common exam trap
Watch out — candidates often confuse CSEK with CMEK; CSEK are not stored in Cloud KMS and do not provide an audit trail.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Customer-managed encryption keys (CMEK) in Cloud KMS
Customer-managed encryption keys (CMEK) in Cloud KMS give the company full control over key creation, rotation, and usage. Cloud KMS integrates with Cloud Audit Logs to record all key operations, providing the required audit trail. Google-managed keys offer no customer control, CSEK lack integrated auditing, and Cloud HSM is a backing option for CMEK rather than a standalone solution.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Google-managed encryption keys
Why it's wrong here
Google-managed encryption keys are default and automatically rotated by Google, but the company does not control them and cannot rotate them on demand. They also do not provide a separate audit trail of key usage beyond what Cloud KMS logs. This option does not meet the requirement for customer control.
- ✓
Customer-managed encryption keys (CMEK) in Cloud KMS
Why this is correct
CMEK in Cloud KMS allows the company to create, rotate, and manage their own keys. Cloud KMS logs key usage through Cloud Audit Logs, providing an audit trail. This option satisfies both the control and audit requirements for data at rest in Cloud Storage.
- ✗
Customer-supplied encryption keys (CSEK)
Why it's wrong here
CSEK are provided by the customer and used by Google to encrypt data, but they are not stored in Cloud KMS, so there is no automatic audit trail of key usage. The customer is responsible for key management and rotation, which can be operationally complex. This option does not provide the integrated audit trail.
- ✗
Cloud HSM
Why it's wrong here
Cloud HSM is a hardware security module service that can be used with Cloud KMS to store keys in hardware, but it is not a standalone encryption key management solution for Cloud Storage. It is part of Cloud KMS and would be used in conjunction with CMEK. This option alone does not meet the requirement without specifying CMEK.
Go deeper
Related to this question
Learn chapter
Resource Monitoring and Logging with Cloud Operations
Key term
Service
A service is a software component or system that performs a specific function and is available to be used by other programs or users over a network.
Key term
Data
Data is raw, unprocessed information, like numbers, words, or measurements, that can be stored, processed, and analyzed by computers.
About these practice questions
One of 807 original PCA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Google Cloud exam blueprint
This PCA practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCA exam.