Google PCA Design for security and compliance Practice Question
A financial services company is migrating a sensitive customer data application to Google Cloud. The application runs on Compute Engine VMs in a VPC. The security team requires that all data at rest in Cloud Storage and BigQuery must be encrypted with customer-managed encryption keys (CMEK). Additionally, the keys must be stored in a different project than the data, and access to the keys must be audited. The operations team has set up a CMEK key in Cloud KMS in a separate project, assigned the Cloud KMS CryptoKey Encrypter/Decrypter role to the data project's Compute Engine service account, and enabled Cloud Storage and BigQuery to use CMEK. However, when the application tries to read from Cloud Storage, it fails with 'Access Denied.' The Cloud KMS key is in project 'kms-proj' and the data is in project 'data-proj'. What is the most likely cause?
⚠ Common exam trap
A common trap on Google Cloud exams is the distinction between the service account used by the compute resource (e.g., Compute Engine VM) and the service agent used by the Google Cloud service (e.g., Cloud Storage), leading candidates to incorrectly assume the VM's service account handles all encryption operations.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The Cloud Storage service agent in 'data-proj' does not have the Cloud KMS CryptoKey Encrypter/Decrypter role.
Cloud Storage uses a Google-managed service agent (not the Compute Engine service account) to interact with CMEK keys. When Cloud Storage is configured to use CMEK, its service agent in the data project must be granted the Cloud KMS CryptoKey Encrypter/Decrypter role on the key in the KMS project. Without this permission, Cloud Storage cannot decrypt the key to access the data, resulting in an 'Access Denied' error even though the VM's service account has the correct role.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The Compute Engine service account used by the VM does not have the Cloud KMS Decrypter role.
Why it's wrong here
The stem already grants the Compute Engine service account the CryptoKey Encrypter/Decrypter role, which includes decrypt permission, so this role is present. This option is tempting because missing IAM permissions are the usual cause of Access Denied, but here the grant is explicitly stated.
- ✗
The VPC firewall rules are blocking egress to Cloud KMS.
Why it's wrong here
Cloud KMS requests travel over Google's internal APIs, not the VPC data plane, so VPC firewall rules never gate them. Firewall egress rules are the correct control when restricting a VM's outbound traffic to external endpoints, which is a different layer entirely.
- ✗
The Cloud KMS key has been disabled due to an Organization Policy.
Why it's wrong here
A disabled Cloud KMS key returns a distinct failure indicating the key is unavailable, and an Organization Policy blocking CMEK would have prevented the bucket from being configured at all. Disabling is the deliberate action taken to revoke cryptographic access during key rotation or incident response.
- ✓
The Cloud Storage service agent in 'data-proj' does not have the Cloud KMS CryptoKey Encrypter/Decrypter role.
Why this is correct
Cloud Storage performs CMEK envelope encryption through its per-project service agent, not the Compute Engine service account. The service agent `service-<project-number>@gs-project-accounts.iam.gserviceaccount.com` in `data-proj` requires the Cloud KMS CryptoKey Encrypter/Decrypter role on the key in `kms-proj`; without it, reads fail with Access Denied.
Go deeper
Related to this question
Learn chapter
Cloud Storage: Objects and Buckets
Key term
Cloud storage
Cloud storage is a service that lets you save data on remote servers accessed over the internet instead of on your computer's hard drive.
Key term
Service account
A service account is a special type of account used by an application or a virtual machine, rather than a human user, to authenticate and interact with cloud services and APIs securely.
About these practice questions
Courseiva writes every PCA question from scratch — 807 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PCA practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCA exam.