Google PCA Practice Question: Managing and Provisioning a Solution Infrastructure
A healthcare company must store patient documents in Cloud Storage. Compliance requires that the data be encrypted with keys the company controls and that key usage be centrally audited and revocable. The architect plans to use Cloud KMS. Which two actions should the architect take to meet these requirements? (Choose two.)
⚠ Common exam trap
The trap here is assuming that enabling uniform bucket-level access or using customer-supplied keys provides the same central auditing and revocation as a Cloud KMS CMEK, when neither does.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create a Cloud KMS key ring and a customer-managed encryption key (CMEK) in the same region as the bucket, and configure the bucket to use that key as its default encryption key.
Meeting the compliance goals requires a customer-managed encryption key configured as the bucket's default encryption key, plus the Cloud Storage service agent holding cryptoKeyEncrypterDecrypter on that key. Together these ensure all objects are encrypted with a company-controlled key and that every key operation is recorded in Cloud Audit Logs, enabling auditing and revocation through Cloud KMS.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Create a customer-supplied encryption key (CSEK) and store it in Secret Manager for each object upload.
Why it's wrong here
Customer-supplied encryption keys are managed entirely by the customer and are not stored or audited by Cloud KMS. Because key usage is not centrally logged or revocable through Cloud KMS, this approach fails the requirement for centralized auditing and revocation of key operations.
- ✗
Enable Cloud External Key Manager (Cloud EKM) backed by keys held in a third-party HSM.
Why it's wrong here
Cloud EKM is appropriate when keys must reside outside Google Cloud in a supported external key manager. The scenario does not require external key custody, and adding Cloud EKM introduces an external dependency without addressing central auditing or revocation any better than a Cloud KMS CMEK.
- ✓
Create a Cloud KMS key ring and a customer-managed encryption key (CMEK) in the same region as the bucket, and configure the bucket to use that key as its default encryption key.
Why this is correct
Using a CMEK as the bucket's default encryption key ensures that every object written to the bucket is encrypted with a key the company controls. Because Cloud KMS logs key operations in Cloud Audit Logs, the company gains centralized visibility and can disable or destroy the key to revoke access, satisfying both compliance requirements.
- ✗
Enable uniform bucket-level access on the bucket to force CMEK usage.
Why it's wrong here
Uniform bucket-level access controls how IAM permissions are evaluated for objects, not how data is encrypted. Enabling it does not cause objects to be encrypted with a customer-managed key, so it does not satisfy the compliance requirement for company-controlled encryption keys.
- ✓
Grant the Cloud Storage service agent the roles/cloudkms.cryptoKeyEncrypterDecrypter role on the CMEK.
Why this is correct
Cloud Storage accesses the CMEK through its service agent, so that identity needs cryptoKeyEncrypterDecrypter on the key. Without this grant, object writes and reads fail with permission errors. Granting the role only on the specific key follows least privilege while enabling the encryption and decryption operations the bucket requires.
Go deeper
Related to this question
Learn chapter
Security Best Practices and Compliance
Key term
Data
Data is raw, unprocessed information, like numbers, words, or measurements, that can be stored, processed, and analyzed by computers.
Key term
Cloud Audit Logs
Cloud Audit Logs are a record of actions taken by users, services, and resources inside a cloud environment, capturing who did what, when, and from where.
About these practice questions
This PCA question is part of Courseiva's 807-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Google Cloud exam blueprint
This PCA practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCA exam.