Courseiva

Google PCA Design for security and compliance Practice Question

A company needs to ensure that all data stored in Cloud Storage is encrypted at rest with keys that they control and can rotate on demand. They also need to maintain an audit trail of key usage. Which Google Cloud service should they use?

⚠ Common exam trap

Watch out — candidates often confuse CSEK with CMEK; CSEK are not stored in Cloud KMS and do not provide an audit trail.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Customer-managed encryption keys (CMEK) in Cloud KMS

Customer-managed encryption keys (CMEK) in Cloud KMS give the company full control over key creation, rotation, and usage. Cloud KMS integrates with Cloud Audit Logs to record all key operations, providing the required audit trail. Google-managed keys offer no customer control, CSEK lack integrated auditing, and Cloud HSM is a backing option for CMEK rather than a standalone solution.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Google-managed encryption keys

    Why it's wrong here

    Google-managed encryption keys are default and automatically rotated by Google, but the company does not control them and cannot rotate them on demand. They also do not provide a separate audit trail of key usage beyond what Cloud KMS logs. This option does not meet the requirement for customer control.

  • ✓

    Customer-managed encryption keys (CMEK) in Cloud KMS

    Why this is correct

    CMEK in Cloud KMS allows the company to create, rotate, and manage their own keys. Cloud KMS logs key usage through Cloud Audit Logs, providing an audit trail. This option satisfies both the control and audit requirements for data at rest in Cloud Storage.

  • ✗

    Customer-supplied encryption keys (CSEK)

    Why it's wrong here

    CSEK are provided by the customer and used by Google to encrypt data, but they are not stored in Cloud KMS, so there is no automatic audit trail of key usage. The customer is responsible for key management and rotation, which can be operationally complex. This option does not provide the integrated audit trail.

  • ✗

    Cloud HSM

    Why it's wrong here

    Cloud HSM is a hardware security module service that can be used with Cloud KMS to store keys in hardware, but it is not a standalone encryption key management solution for Cloud Storage. It is part of Cloud KMS and would be used in conjunction with CMEK. This option alone does not meet the requirement without specifying CMEK.

About these practice questions

One of 807 original PCA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Google Cloud exam blueprint

This PCA practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCA exam.