Courseiva

Google PCA Design and plan a cloud solution architecture Practice Question

A healthcare company is planning to store sensitive patient records in Cloud Storage. They need to ensure that the data is encrypted at rest with keys that they control and can rotate on demand. They also want to maintain an audit trail of key usage. Which Google Cloud service should they use?

⚠ Common exam trap

It's easy for candidates to confuse customer-supplied encryption keys with customer-managed keys; the former does not provide audit logs because Google never sees the keys.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Cloud Key Management Service (Cloud KMS) with customer-managed encryption keys (CMEK).

Cloud KMS with customer-managed encryption keys gives the company full control over key creation, rotation, and usage. It integrates with Cloud Audit Logs to record key operations. The other options either do not provide customer control, lack auditability, or are not specific to the requirement.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Cloud HSM with a hardware security module for key storage.

    Why it's wrong here

    Cloud HSM is a service that provides hardware-backed key storage, but it is part of Cloud KMS. Using Cloud HSM alone without specifying CMEK does not directly address the need for customer-managed keys for Cloud Storage. The scenario requires control over keys and auditability, which Cloud KMS with CMEK provides; Cloud HSM is an option within that.

  • ✗

    Customer-supplied encryption keys (CSEK) stored on-premises.

    Why it's wrong here

    CSEK allows you to provide your own encryption keys, but you are responsible for storing and managing them. Google does not store these keys, so there is no audit trail of key usage within Google Cloud. The requirement includes an audit trail, which CSEK does not provide.

  • ✓

    Cloud Key Management Service (Cloud KMS) with customer-managed encryption keys (CMEK).

    Why this is correct

    Cloud KMS allows you to create and manage encryption keys, including customer-managed keys. You can rotate these keys on demand and integrate with Cloud Audit Logs to track key usage. This meets the requirements for controlling keys and maintaining an audit trail.

  • ✗

    Cloud Storage default encryption with Google-managed keys.

    Why it's wrong here

    Google-managed keys are automatically handled by Google, but the company does not control them and cannot rotate them on demand. While encryption at rest is provided, the requirement for customer control and auditability of key usage is not satisfied.

About these practice questions

Courseiva writes every PCA question from scratch — 807 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Google Cloud exam blueprint

This PCA practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCA exam.