Google PCA Design for security and compliance Practice Question
A healthcare company stores patient records in Cloud Storage and BigQuery. Auditors require that cryptographic keys used to protect this data are generated and stored on hardware security modules, that key material never leaves Google's infrastructure, and that the company retains the ability to control key rotation and revocation. The security team wants the least operational overhead while meeting these requirements. Which key management approach should the architect select?
⚠ Common exam trap
The trap here is assuming that any customer-controlled key option satisfies the hardware security module requirement, when CSEK and client-side keys are customer-held software keys with no HSM backing.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Customer-managed encryption keys (CMEK) backed by Cloud KMS with a Cloud HSM protection level
Customer-managed encryption keys using Cloud KMS with the Cloud HSM protection level satisfy all three auditor conditions: hardware security module key generation and storage, key material confined to Google infrastructure, and customer control over rotation and revocation. CSEK and client-side encryption move key custody to the customer and add heavy operational cost, while Google-managed keys remove the customer control the auditors demanded.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Google-managed encryption keys with default encryption at rest
Why it's wrong here
Google-managed keys protect data at rest but the customer has no control over rotation, no ability to revoke the key to render data unreadable, and no visibility into the HSM backing the key. This fails the auditor requirement for customer-controlled key lifecycle and hardware-backed key material.
- ✗
Customer-supplied encryption keys (CSEK) managed in the company's own on-premises key vault
Why it's wrong here
CSEK puts the full burden of key generation, storage, rotation, and availability on the customer, and the raw key is transmitted to Google with each request. This is far more operational overhead than required, and losing the key means permanent, unrecoverable data loss, which is risky for regulated patient records.
- ✗
Client-side encryption performed by the application before writing objects to Cloud Storage
Why it's wrong here
Client-side encryption keeps keys entirely outside Google, so key material never resides in an HSM managed by Google, and it does nothing for data queried directly in BigQuery. It also pushes key management and query-compatibility work onto the application team, adding significant overhead.
- ✓
Customer-managed encryption keys (CMEK) backed by Cloud KMS with a Cloud HSM protection level
Why this is correct
CMEK with a Cloud HSM protection level generates and stores key material inside FIPS 140-2 Level 3 validated hardware security modules, and the key never leaves Google infrastructure. The organization controls rotation schedules, IAM bindings on the key, and can disable or destroy the key to revoke access, satisfying the auditors with minimal operational burden.
Go deeper
Related to this question
Learn chapter
Cloud Storage: Objects and Buckets
Key term
Hardware security module
A specialized hardware appliance that securely generates, stores, and manages cryptographic keys in a tamper-resistant environment for enterprise security systems.
Key term
KMS
KMS (Key Management Service) is a Microsoft technology that automates volume licensing activation for Windows and Office products within an organization's network.
About these practice questions
Courseiva writes every PCA question from scratch — 807 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Google Cloud exam blueprint
This PCA practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCA exam.