mediumMultiple Choice
Google PCA Practice Question: A company uses Cloud Storage to store sensitive…
A company uses Cloud Storage to store sensitive customer data. They must ensure that data at rest is encrypted with a customer-managed key that is automatically rotated every 90 days. Which Cloud Storage configuration should they use?
⚠ Common exam trap
PCA often tests the distinction between CMEK (customer-managed, Cloud KMS-rotatable) and CSEK (customer-supplied, not stored, not auto-rotatable), as well as the misconception that key rotation re-encrypts existing objects.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Enable default encryption with a customer-managed key (CMEK) from Cloud KMS with automatic rotation set to 90 days
Cloud KMS customer-managed encryption keys (CMEK) can be configured as the default encryption key for a Cloud Storage bucket, and Cloud KMS supports automatic rotation schedules (e.g., every 90 days). This satisfies both requirements: customer-managed key and automatic 90-day rotation, with no manual intervention.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Use customer-supplied encryption keys (CSEK) and rotate them manually
Why it's wrong here
CSEK keys are supplied and rotated by the customer, so automatic 90-day rotation cannot occur; the stem demands rotation managed by the provider. CSEK suits organisations that must retain full key custody outside Google's systems, for example regulatory mandates forbidding provider-held keys.
- ✓
Enable default encryption with a customer-managed key (CMEK) from Cloud KMS with automatic rotation set to 90 days
Why this is correct
A CMEK from Cloud KMS with a 90-day rotation schedule encrypts objects at rest under a key the customer controls and rotates, meeting both the customer-managed and automatic rotation constraints. Google-managed keys cannot satisfy the rotation requirement.
- ✗
Use Cloud HSM to create a key and set the bucket to use that key without rotation policy
Why it's wrong here
Cloud HSM keys can be customer-managed, but the option explicitly omits a rotation policy, so the 90-day automatic rotation requirement is unmet. It is tempting because Cloud HSM provides strong key custody, and would be correct if rotation were configured separately via Cloud KMS.
- ✗
Use Google-managed encryption keys (SSE-GM)
Why it's wrong here
SSE-GM uses Google-managed keys, so the customer neither owns nor rotates the key material, failing the customer-managed and 90-day rotation requirements. It is tempting because it is the default, zero-configuration option, and would be correct if the requirement were only encryption at rest.
Go deeper
Related to this question
Learn chapter
Cloud Storage: Objects and Buckets
Key term
CAN
A CAN (Controller Area Network) is a robust vehicle bus standard designed to allow microcontrollers and devices to communicate with each other without a host computer.
Key term
Cloud storage
Cloud storage is a service that lets you save data on remote servers accessed over the internet instead of on your computer's hard drive.
About these practice questions
One of 807 original PCA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Google Cloud exam blueprint
This PCA practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCA exam.