Google PCA Design and plan a cloud solution architecture Practice Question
A financial services firm is designing a new payment-processing platform on Google Cloud. Regulatory requirements mandate that data never leaves the European Union, that encryption keys are generated and stored on hardware the firm controls inside its own data center, and that the firm can revoke key access instantly. The security team wants to use Cloud KMS but is unsure it meets all three requirements. Which combination of services should the architect recommend?
⚠ Common exam trap
The trap here is treating Cloud HSM or CMEK as equivalent to holding keys in your own data center, when Google still operates that hardware.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Cloud External Key Manager (Cloud EKM) with a supported external key manager in the firm's data center, plus organization policy constraints to restrict resource locations.
The three requirements are EU data residency, self-controlled key hardware, and instant revocation. Only an external key manager integration satisfies all three because the keys physically live in the firm's data center and Google must reach out to them for every unwrap operation. Location constraints in organization policy handle the residency requirement, and severing the external key path provides the immediate revocation the security team wants.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Customer-managed encryption keys (CMEK) stored in a Cloud KMS key ring in europe-west1, with Cloud HSM backing.
Why it's wrong here
CMEK with Cloud HSM gives the firm control over key rotation, usage, and IAM, and Cloud HSM stores keys in FIPS 140-2 Level 3 validated hardware. However, that hardware is operated by Google, not located in the firm's own data center, so the requirement for self-controlled hardware is unmet. Revocation is also limited to disabling or destroying the key version, which is not the same as cutting external access.
- ✓
Cloud External Key Manager (Cloud EKM) with a supported external key manager in the firm's data center, plus organization policy constraints to restrict resource locations.
Why this is correct
Cloud EKM lets Cloud KMS call out to a supported external key manager that the firm operates, so keys are generated and stored on hardware inside its own data center while Google services use them through the KMS interface. If the firm cuts connectivity or disables the external key, Google loses the ability to unwrap data encryption keys, giving effectively instant revocation. Organization policy keeps resources in EU locations.
- ✗
Cloud KMS with CMEK and a key ring in europe-west4, combined with VPC Service Controls perimeters around all data services.
Why it's wrong here
VPC Service Controls perimeters limit data exfiltration and key rings in europe-west4 keep key material in the EU, but neither addresses where the keys are generated or stored. Google still holds the key material on its own infrastructure. This option strengthens the network and location posture but does not satisfy the control-of-hardware requirement, so revocation cannot be achieved by withdrawing external access.
- ✗
Cloud KMS with a multi-region key ring in europe, plus organization policy constraints to restrict resource locations.
Why it's wrong here
Cloud KMS multi-region key rings in europe keep key material within the EU and organization policy can restrict where resources are created, but Google still generates and stores the key material. The requirement that keys be generated and stored on hardware the firm controls in its own data center is not met, and instant revocation of a Google-held key is limited to disabling or destroying it, not withdrawing external key access.
Go deeper
Related to this question
Learn chapter
Introduction to Google Cloud Platform
Key term
Data
Data is raw, unprocessed information, like numbers, words, or measurements, that can be stored, processed, and analyzed by computers.
Key term
CAN
A CAN (Controller Area Network) is a robust vehicle bus standard designed to allow microcontrollers and devices to communicate with each other without a host computer.
About these practice questions
This PCA question is part of Courseiva's 807-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Google Cloud exam blueprint
This PCA practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCA exam.