Google PCA Designing for Security and Compliance Practice Question
A healthcare company stores sensitive patient data in Cloud Storage. They must ensure that data is encrypted at rest with a key that they manage, and that the key is automatically rotated every 90 days. They also need to be able to audit key usage. Which approach should they take?
⚠ Common exam trap
The trap here is assuming that organization policy constraints automatically apply a specific CMEK, when they only enforce that some CMEK is used.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create a Cloud KMS key with a rotation period of 90 days, grant the Cloud Storage service account encrypt/decrypt permissions on the key, and configure the bucket to use that key as the default encryption key.
Cloud KMS provides automatic key rotation and audit logging. By setting a bucket default key, all objects are encrypted with the CMEK. Granting the Cloud Storage service account encrypt/decrypt permissions is required for the bucket to use the key. This approach meets encryption, rotation, and auditing requirements with minimal overhead.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Use a Cloud HSM key with a rotation period of 90 days, and configure the bucket with a retention policy that enforces encryption.
Why it's wrong here
Cloud HSM keys can be rotated, but a bucket retention policy does not enforce encryption; it only prevents object deletion or modification. This option does not ensure the bucket uses the CMEK. Additionally, Cloud HSM is for hardware-backed keys, which may be overkill and not required by the scenario.
- ✗
Use Customer-Supplied Encryption Keys (CSEK) with a 90-day rotation managed by the application, and enable Cloud Audit Logs for Cloud Storage.
Why it's wrong here
CSEK are managed by the customer and not stored in Cloud KMS; rotation must be handled manually or by the application. This adds significant operational overhead and does not provide automatic rotation. Cloud Audit Logs for Cloud Storage log API calls but do not audit key usage as Cloud KMS does.
- ✓
Create a Cloud KMS key with a rotation period of 90 days, grant the Cloud Storage service account encrypt/decrypt permissions on the key, and configure the bucket to use that key as the default encryption key.
Why this is correct
Cloud KMS supports automatic key rotation, which can be set to 90 days. Granting the Cloud Storage service account permissions on the key allows the bucket to use it for encryption. Setting the bucket default key ensures all objects are encrypted with the CMEK. Cloud KMS audit logs capture key usage, meeting the auditing requirement.
- ✗
Create a Cloud KMS key with a rotation period of 90 days, and use an organization policy constraint to require CMEK on all Cloud Storage buckets.
Why it's wrong here
An organization policy constraint can require CMEK, but it does not automatically apply a specific key to a bucket. The bucket must still be configured to use the key. This option lacks the necessary bucket-level configuration and permissions for the Cloud Storage service account.
Go deeper
Related to this question
Learn chapter
Data Migration and Transfer Services
Key term
Cloud KMS
Cloud KMS (Key Management Service) is a cloud-based service that lets you create, manage, and use encryption keys to protect your data at rest and in transit.
Key term
Service account
A service account is a special type of account used by an application or a virtual machine, rather than a human user, to authenticate and interact with cloud services and APIs securely.
About these practice questions
Courseiva writes every PCA question from scratch — 807 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Google Cloud exam blueprint
This PCA practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCA exam.