Google PCA Design for security and compliance Practice Question
A financial services company must comply with PCI DSS. They use Cloud SQL for MySQL for transaction processing. They need to ensure that all data at rest is encrypted with keys generated and stored in a Hardware Security Module (HSM) and that key rotation occurs every 90 days. Which configuration should they use?
⚠ Common exam trap
Many candidates confuse CSEK with CMEK, assuming CSEK provides HSM-backed keys, but CSEK keys are stored in Cloud KMS software, not in an HSM, and cannot be automatically rotated for Cloud SQL.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use Cloud SQL with CMEK backed by Cloud HSM, and set automatic rotation period of 90 days
Cloud SQL with CMEK backed by Cloud HSM meets the requirement for keys generated and stored in an HSM, and Cloud HSM supports automatic key rotation with a configurable period, including 90 days. CMEK allows you to manage and rotate the key used to encrypt data at rest, while Cloud HSM provides FIPS 140-2 Level 3 validated HSM for key storage. The automatic rotation period can be set to 90 days via the key rotation policy in Cloud KMS, satisfying the compliance mandate.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Use Cloud External Key Manager (EKM) to integrate with on-premises HSM
Why it's wrong here
EKM is possible but not the simplest; also rotation management depends on external system.
- ✗
Use Cloud SQL with customer-supplied encryption keys (CSEK) and automate rotation with Cloud Scheduler
Why it's wrong here
CSEK is for Compute Engine persistent disks, not Cloud SQL.
- ✓
Use Cloud SQL with CMEK backed by Cloud HSM, and set automatic rotation period of 90 days
Why this is correct
CMEK with Cloud HSM provides customer-controlled, HSM-backed keys with automatic rotation.
- ✗
Use Cloud SQL's default encryption with organization policy requiring rotation
Why it's wrong here
Default encryption uses Google-managed keys, not HSM.
Go deeper
Related to this question
Learn chapter
Data Migration and Transfer Services
Key term
Cloud KMS
Cloud KMS (Key Management Service) is a cloud-based service that lets you create, manage, and use encryption keys to protect your data at rest and in transit.
Key term
Data
Data is raw, unprocessed information, like numbers, words, or measurements, that can be stored, processed, and analyzed by computers.
About these practice questions
Courseiva writes every PCA question from scratch — 807 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PCA practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCA exam.