Courseiva

Google PCA Practice Question: Managing and Provisioning a Solution Infrastructure

A healthcare company must store patient documents in Cloud Storage. Compliance requires that the data be encrypted with keys the company controls and that key usage be centrally audited and revocable. The architect plans to use Cloud KMS. Which two actions should the architect take to meet these requirements? (Choose two.)

⚠ Common exam trap

The trap here is assuming that enabling uniform bucket-level access or using customer-supplied keys provides the same central auditing and revocation as a Cloud KMS CMEK, when neither does.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Create a Cloud KMS key ring and a customer-managed encryption key (CMEK) in the same region as the bucket, and configure the bucket to use that key as its default encryption key.

Meeting the compliance goals requires a customer-managed encryption key configured as the bucket's default encryption key, plus the Cloud Storage service agent holding cryptoKeyEncrypterDecrypter on that key. Together these ensure all objects are encrypted with a company-controlled key and that every key operation is recorded in Cloud Audit Logs, enabling auditing and revocation through Cloud KMS.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Create a customer-supplied encryption key (CSEK) and store it in Secret Manager for each object upload.

    Why it's wrong here

    Customer-supplied encryption keys are managed entirely by the customer and are not stored or audited by Cloud KMS. Because key usage is not centrally logged or revocable through Cloud KMS, this approach fails the requirement for centralized auditing and revocation of key operations.

  • ✗

    Enable Cloud External Key Manager (Cloud EKM) backed by keys held in a third-party HSM.

    Why it's wrong here

    Cloud EKM is appropriate when keys must reside outside Google Cloud in a supported external key manager. The scenario does not require external key custody, and adding Cloud EKM introduces an external dependency without addressing central auditing or revocation any better than a Cloud KMS CMEK.

  • ✓

    Create a Cloud KMS key ring and a customer-managed encryption key (CMEK) in the same region as the bucket, and configure the bucket to use that key as its default encryption key.

    Why this is correct

    Using a CMEK as the bucket's default encryption key ensures that every object written to the bucket is encrypted with a key the company controls. Because Cloud KMS logs key operations in Cloud Audit Logs, the company gains centralized visibility and can disable or destroy the key to revoke access, satisfying both compliance requirements.

  • ✗

    Enable uniform bucket-level access on the bucket to force CMEK usage.

    Why it's wrong here

    Uniform bucket-level access controls how IAM permissions are evaluated for objects, not how data is encrypted. Enabling it does not cause objects to be encrypted with a customer-managed key, so it does not satisfy the compliance requirement for company-controlled encryption keys.

  • ✓

    Grant the Cloud Storage service agent the roles/cloudkms.cryptoKeyEncrypterDecrypter role on the CMEK.

    Why this is correct

    Cloud Storage accesses the CMEK through its service agent, so that identity needs cryptoKeyEncrypterDecrypter on the key. Without this grant, object writes and reads fail with permission errors. Granting the role only on the specific key follows least privilege while enabling the encryption and decryption operations the bucket requires.

About these practice questions

This PCA question is part of Courseiva's 807-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Google Cloud exam blueprint

This PCA practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCA exam.