Google PCA Design and plan a cloud solution architecture Practice Question
A financial services company runs a payment processing platform on Compute Engine. Compliance requires that all data at rest be encrypted with keys the company controls and that key material never leave their on-premises HSM appliances. They must also minimize operational overhead for key rotation. Which Google Cloud solution should the architect recommend?
⚠ Common exam trap
The trap here is assuming that CMEK via Cloud KMS keeps key material on-premises, when in fact Cloud KMS holds the key material unless Cloud EKM is used.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Cloud External Key Manager (Cloud EKM) with an external key manager
The strict requirement is that key material must remain in the company's on-premises HSMs while still protecting Google Cloud resources. Cloud EKM is designed exactly for this: it lets Cloud services use CMEK backed by an external key manager, so Google never holds the key material. CSEK requires manual key handling, Cloud KMS stores keys in Google Cloud, and default encryption gives no customer control.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Default Google-managed encryption at rest with CMEK disabled
Why it's wrong here
Google-managed encryption keys protect data at rest by default, but the company has no control over key material or rotation, and the keys reside within Google's infrastructure. This directly conflicts with the requirement that keys stay in the company's on-premises HSMs. While operationally simple, it fails the core compliance constraint, so it cannot be the recommended architecture for this payment platform.
- ✗
Customer-supplied encryption keys (CSEK) stored in a local vault
Why it's wrong here
CSEK lets you supply your own AES-256 keys for Compute Engine disks, but you must provide the key on every API call and manage rotation and availability yourself. It does not integrate with an on-premises HSM for automated wrap/unwrap, and it increases operational overhead rather than reducing it. The scenario explicitly asks to minimize overhead, so CSEK is a weaker fit than a managed external key manager integration.
- ✓
Cloud External Key Manager (Cloud EKM) with an external key manager
Why this is correct
Cloud EKM allows Compute Engine disks and other resources to use CMEK whose key material lives in an external key manager, including on-premises HSM-backed systems. Google never sees the key material; it only sends wrap/unwrap requests. This satisfies the requirement that keys remain in the company's HSMs while still integrating with Google Cloud services, and rotation is handled in the external key manager.
- ✗
Cloud KMS with CMEK and automatic rotation
Why it's wrong here
Cloud KMS with CMEK lets the organization control keys and rotation schedules, but the key material is generated and stored in Google Cloud KMS, not in on-premises HSM appliances. The requirement that key material never leave the company's own HSMs is therefore violated. This option addresses rotation overhead but fails the strict key custody constraint, so it is not the right recommendation for this scenario.
Go deeper
Related to this question
Learn chapter
Data Migration and Transfer Services
Key term
Data
Data is raw, unprocessed information, like numbers, words, or measurements, that can be stored, processed, and analyzed by computers.
Key term
Cloud KMS
Cloud KMS (Key Management Service) is a cloud-based service that lets you create, manage, and use encryption keys to protect your data at rest and in transit.
About these practice questions
Courseiva writes every PCA question from scratch — 807 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Google Cloud exam blueprint
This PCA practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCA exam.