Courseiva
mediumMultiple Choice

Google PCA Practice Question: A company uses Cloud Storage to store sensitive…

A company uses Cloud Storage to store sensitive customer data. They must ensure that data at rest is encrypted with a customer-managed key that is automatically rotated every 90 days. Which Cloud Storage configuration should they use?

⚠ Common exam trap

PCA often tests the distinction between CMEK (customer-managed, Cloud KMS-rotatable) and CSEK (customer-supplied, not stored, not auto-rotatable), as well as the misconception that key rotation re-encrypts existing objects.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Enable default encryption with a customer-managed key (CMEK) from Cloud KMS with automatic rotation set to 90 days

Cloud KMS customer-managed encryption keys (CMEK) can be configured as the default encryption key for a Cloud Storage bucket, and Cloud KMS supports automatic rotation schedules (e.g., every 90 days). This satisfies both requirements: customer-managed key and automatic 90-day rotation, with no manual intervention.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Use customer-supplied encryption keys (CSEK) and rotate them manually

    Why it's wrong here

    CSEK keys are supplied and rotated by the customer, so automatic 90-day rotation cannot occur; the stem demands rotation managed by the provider. CSEK suits organisations that must retain full key custody outside Google's systems, for example regulatory mandates forbidding provider-held keys.

  • ✓

    Enable default encryption with a customer-managed key (CMEK) from Cloud KMS with automatic rotation set to 90 days

    Why this is correct

    A CMEK from Cloud KMS with a 90-day rotation schedule encrypts objects at rest under a key the customer controls and rotates, meeting both the customer-managed and automatic rotation constraints. Google-managed keys cannot satisfy the rotation requirement.

  • ✗

    Use Cloud HSM to create a key and set the bucket to use that key without rotation policy

    Why it's wrong here

    Cloud HSM keys can be customer-managed, but the option explicitly omits a rotation policy, so the 90-day automatic rotation requirement is unmet. It is tempting because Cloud HSM provides strong key custody, and would be correct if rotation were configured separately via Cloud KMS.

  • ✗

    Use Google-managed encryption keys (SSE-GM)

    Why it's wrong here

    SSE-GM uses Google-managed keys, so the customer neither owns nor rotates the key material, failing the customer-managed and 90-day rotation requirements. It is tempting because it is the default, zero-configuration option, and would be correct if the requirement were only encryption at rest.

About these practice questions

One of 807 original PCA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Google Cloud exam blueprint

This PCA practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCA exam.