Courseiva

Google PCA Practice Question: Managing and Provisioning a Solution Infrastructure

A healthcare analytics company stores protected health information in Cloud Storage buckets. Auditors require that data be encrypted with customer-managed encryption keys (CMEK) and that key usage be logged separately from data access. The security team wants the ability to revoke access to the data by disabling a single key without deleting the data. Which configuration should the architect recommend?

⚠ Common exam trap

Test-takers frequently confuse CSEK with CMEK, since both involve customer-supplied key material but only Cloud KMS CMEK provides centralized audit logging and disable-to-revoke behavior.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Create a Cloud KMS key ring and key in the same region as the bucket, set the bucket's default KMS key to that key, and enable Cloud KMS Data Access audit logs.

Customer-managed encryption keys in Cloud KMS let the organization control key lifecycle, and setting a bucket's default KMS key applies CMEK to every object automatically. Cloud KMS Data Access audit logs capture cryptographic operations independently of Cloud Storage access logs, meeting the separation requirement. Disabling the key version immediately makes objects unreadable, achieving revocation without deleting data, which is exactly the auditor's ask.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Enable Bucket Lock on the bucket and configure a retention policy, then use Google-managed keys with Object Lifecycle Management to transition objects to Coldline storage.

    Why it's wrong here

    Bucket Lock and retention policies prevent deletion or modification of objects for a period; they do not provide customer-controlled encryption or key revocation. Google-managed keys remain outside the organization's control, and lifecycle transitions do not change the encryption key model. This configuration addresses immutability, not the CMEK and key-logging requirements stated by the auditors.

  • ✗

    Use Google-managed encryption keys and enable Data Access audit logs on the bucket to record every object read and write.

    Why it's wrong here

    Google-managed keys do not give the organization control over key lifecycle, so it cannot revoke access by disabling a key. Data Access audit logs record who accessed objects but do not provide cryptographic revocation. The auditors specifically require customer-managed keys and separate key-usage logging, neither of which is satisfied by default encryption plus audit logs.

  • ✓

    Create a Cloud KMS key ring and key in the same region as the bucket, set the bucket's default KMS key to that key, and enable Cloud KMS Data Access audit logs.

    Why this is correct

    CMEK on a Cloud Storage bucket is configured by setting a default KMS key, which must be in the same location as the bucket. Cloud KMS Data Access audit logs record every cryptographic operation separately from Cloud Storage data access logs, satisfying the separation requirement. Disabling the key version or the key itself renders the data unreadable without deleting objects, enabling revocation.

  • ✗

    Store the data in a Cloud Storage bucket encrypted with a customer-supplied encryption key (CSEK) and rotate the key by re-uploading all objects with a new key each quarter.

    Why it's wrong here

    CSEKs are provided per request and are not managed in Cloud KMS, so there is no centralized key-usage audit log and no simple disable-to-revoke control. Rotation requires rewriting every object, which is operationally heavy and error-prone at scale. The scenario asks for a managed key with independent logging and a single revocation action, which CSEK does not deliver.

About these practice questions

One of 807 original PCA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Google Cloud exam blueprint

This PCA practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCA exam.