Courseiva

Google PCA Designing for Security and Compliance Practice Question

A financial services firm stores sensitive customer transaction data in Cloud Storage buckets. The security team wants to ensure that the data is encrypted at rest with a key that the firm controls, and that the key is automatically rotated every 90 days. They also need to be able to revoke access to the data immediately by disabling the key. Which Google Cloud service and configuration should they use?

⚠ Common exam trap

Many exam-takers confuse CMEK with CSEK; CSEK requires you to manage keys entirely, without Cloud KMS rotation or disablement features.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Use Customer-Managed Encryption Keys (CMEK) with Cloud KMS, set a rotation period of 90 days, and disable the key to revoke access.

Customer-Managed Encryption Keys (CMEK) with Cloud KMS allow organizations to control the encryption keys used for data at rest in Cloud Storage. You can set an automatic rotation period, such as 90 days, and disabling the key immediately revokes access to the data. This satisfies the requirements for control, automatic rotation, and immediate revocation.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Use Customer-Managed Encryption Keys (CMEK) with Cloud KMS, set a rotation period of 90 days, and disable the key to revoke access.

    Why this is correct

    CMEK allows you to use your own keys in Cloud KMS to encrypt data in Cloud Storage. You can configure automatic rotation every 90 days, and disabling the key immediately prevents decryption, effectively revoking access. This meets all requirements: control over encryption, automatic rotation, and immediate revocation.

  • ✗

    Use Customer-Supplied Encryption Keys (CSEK) and store the keys in a secure vault, rotating them manually every 90 days.

    Why it's wrong here

    CSEK requires you to provide and manage the encryption keys yourself, but Cloud KMS does not manage these keys, so automatic rotation is not supported. You would need to manually rotate and update the keys, which is error-prone. Additionally, disabling a key is not a built-in feature; you would have to stop using the key, but existing data would remain encrypted with the old key.

  • ✗

    Use Google-managed encryption keys and configure a Cloud Scheduler job to rotate the keys every 90 days.

    Why it's wrong here

    Google-managed encryption keys are fully managed by Google, and you cannot control their rotation schedule or manually disable them. Cloud Scheduler cannot rotate Google-managed keys because the rotation is handled internally by Google. This approach does not give the firm control over the key lifecycle or the ability to revoke access by disabling a key, which are both required.

  • ✗

    Use Cloud HSM to generate keys, and configure Cloud Storage to use those keys with a 90-day rotation policy.

    Why it's wrong here

    Cloud HSM is a service that provides hardware security modules for key generation and cryptographic operations, but it is not directly integrated with Cloud Storage for automatic encryption. You would still need to use CMEK with Cloud KMS, and Cloud HSM can be used as a key backend. However, Cloud Storage does not automatically use Cloud HSM keys without CMEK configuration.

About these practice questions

One of 807 original PCA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Google Cloud exam blueprint

This PCA practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCA exam.