Google PCA Design for security and compliance Practice Question
A company wants to automatically rotate cryptographic keys on a schedule without manual intervention. Which service should they use?
⚠ Common exam trap
Google often tests the distinction between key management (KMS) and secret storage (Secret Manager), leading candidates to confuse automated key rotation with simple secret versioning.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Cloud Key Management Service (KMS)
Cloud KMS provides built-in key rotation capabilities that allow you to automatically rotate cryptographic keys on a schedule (e.g., every 90 days) without manual intervention. You define a rotation period, and KMS automatically generates a new primary key version while retaining older versions for decryption of existing data. This is the correct service because it is specifically designed for managing encryption keys with automated lifecycle policies.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Cloud Key Management Service (KMS)
Why this is correct
Cloud KMS supports automatic, scheduled rotation of cryptographic keys, satisfying the requirement for rotation without manual intervention. You configure a rotation period and the service generates new key versions on that schedule, while older versions remain available for decryption. This removes the operational burden of manual rotation entirely.
- ✗
Secret Manager
Why it's wrong here
Secret Manager rotates secrets such as database passwords and API keys, storing credentials rather than cryptographic key material. Scheduled rotation of encryption keys is performed by Cloud KMS, which manages key versions and rotation periods. Secret Manager would be correct for rotating application credentials, not customer-managed encryption keys.
- ✗
Cloud Audit Logs
Why it's wrong here
Cloud Audit Logs records administrative activity and data access events for compliance and forensics; it is read-only telemetry and cannot rotate anything. Cloud KMS performs scheduled key rotation by generating new key versions. Audit Logs would be the right choice for evidencing who used a key and when.
- ✗
Cloud IAM
Why it's wrong here
Cloud IAM manages identities, roles and access policies; it holds no key material and offers no rotation schedule. Automatic cryptographic key rotation is a function of Cloud KMS, which versions keys and rotates them on a configured period. IAM would be the right choice for granting least-privilege access to those keys.
Go deeper
Related to this question
Learn chapter
Data Migration and Transfer Services
Key term
Primary key
A primary key is a unique identifier for each record in a database table, ensuring that no two rows have the same value in that column.
Key term
Service
A service is a software component or system that performs a specific function and is available to be used by other programs or users over a network.
About these practice questions
Courseiva writes every PCA question from scratch — 807 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PCA practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCA exam.