Google PCA Design and plan a cloud solution architecture Practice Question
A healthcare company is designing a new patient portal on Google Cloud. Regulatory requirements mandate that all data at rest be encrypted with keys the company controls and can rotate on its own schedule, and that the keys never leave a hardware security module (HSM). The security team also wants to retain the ability to revoke Google's access to the data if the external key becomes unavailable. Which key management design should you recommend?
⚠ Common exam trap
The trap here is treating Cloud KMS CMEK with HSM protection level as equivalent to externally held keys, when the key material still resides in Google Cloud.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use Cloud External Key Manager (Cloud EKM) with a supported external key management partner and an HSM-backed external key.
Cloud External Key Manager is the only option that keeps key material outside Google Cloud in a partner HSM while still integrating with Google Cloud services for encryption at rest. It supports customer-controlled rotation and, critically, allows the customer to revoke Google's access by disabling the external key. CMEK and GMEK keep key custody inside Google, which does not meet the external control and revocation mandate.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Create a Cloud KMS key ring with HSM protection level and use customer-managed encryption keys (CMEK) for the services.
Why it's wrong here
CMEK with HSM protection level gives the customer control over rotation and keeps key material in an HSM, but the keys are still hosted inside Google Cloud. Google retains the ability to use the key material to decrypt data, so the customer cannot externally revoke access by withholding a key. This misses the external key custody and revocation requirement.
- ✗
Encrypt data with application-level keys stored in Secret Manager and decrypt in the application before writing to Cloud Storage.
Why it's wrong here
Application-level encryption can give the customer control, but storing the keys in Secret Manager places them in Google Cloud, so the customer cannot externally revoke Google's access. It also does not guarantee HSM residency for the key material and requires custom crypto code, which is error-prone and does not integrate with service-level encryption at rest. This fails the HSM and external custody requirements.
- ✗
Use Google-managed encryption keys (GMEK) with default Cloud KMS encryption for all services.
Why it's wrong here
Google-managed encryption keys are fully controlled by Google, so the customer cannot rotate them on demand or enforce that they remain inside an HSM under customer authority. They also do not provide a customer-controlled mechanism to revoke Google's access to the data. This design fails both the key-control and revocation requirements of the scenario.
- ✓
Use Cloud External Key Manager (Cloud EKM) with a supported external key management partner and an HSM-backed external key.
Why this is correct
Cloud EKM lets the customer hold key material in an external, partner-hosted HSM while Google Cloud services call out to wrap and unwrap data encryption keys. The customer controls rotation on their own schedule, key material never resides in Google's infrastructure, and disabling or revoking the external key immediately prevents Google from decrypting the data, satisfying the revocation requirement.
Go deeper
Related to this question
Learn chapter
Cloud SQL and Managed Data Stores
Key term
Hardware security module
A specialized hardware appliance that securely generates, stores, and manages cryptographic keys in a tamper-resistant environment for enterprise security systems.
Key term
CAN
A CAN (Controller Area Network) is a robust vehicle bus standard designed to allow microcontrollers and devices to communicate with each other without a host computer.
About these practice questions
One of 807 original PCA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Google Cloud exam blueprint
This PCA practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCA exam.