Courseiva

Google PCA Design for security and compliance Practice Question

A financial services company must comply with PCI DSS. They use Cloud SQL for MySQL for transaction processing. They need to ensure that all data at rest is encrypted with keys generated and stored in a Hardware Security Module (HSM) and that key rotation occurs every 90 days. Which configuration should they use?

⚠ Common exam trap

Many candidates confuse CSEK with CMEK, assuming CSEK provides HSM-backed keys, but CSEK keys are stored in Cloud KMS software, not in an HSM, and cannot be automatically rotated for Cloud SQL.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Use Cloud SQL with CMEK backed by Cloud HSM, and set automatic rotation period of 90 days

Cloud SQL with CMEK backed by Cloud HSM meets the requirement for keys generated and stored in an HSM, and Cloud HSM supports automatic key rotation with a configurable period, including 90 days. CMEK allows you to manage and rotate the key used to encrypt data at rest, while Cloud HSM provides FIPS 140-2 Level 3 validated HSM for key storage. The automatic rotation period can be set to 90 days via the key rotation policy in Cloud KMS, satisfying the compliance mandate.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Use Cloud External Key Manager (EKM) to integrate with on-premises HSM

    Why it's wrong here

    EKM is possible but not the simplest; also rotation management depends on external system.

  • ✗

    Use Cloud SQL with customer-supplied encryption keys (CSEK) and automate rotation with Cloud Scheduler

    Why it's wrong here

    CSEK is for Compute Engine persistent disks, not Cloud SQL.

  • ✓

    Use Cloud SQL with CMEK backed by Cloud HSM, and set automatic rotation period of 90 days

    Why this is correct

    CMEK with Cloud HSM provides customer-controlled, HSM-backed keys with automatic rotation.

  • ✗

    Use Cloud SQL's default encryption with organization policy requiring rotation

    Why it's wrong here

    Default encryption uses Google-managed keys, not HSM.

About these practice questions

Courseiva writes every PCA question from scratch — 807 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PCA practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCA exam.