Courseiva

Google PCA Designing for Security and Compliance Practice Question

A healthcare company stores sensitive patient data in Cloud Storage. They must ensure that data is encrypted at rest with a key that they manage, and that the key is automatically rotated every 90 days. They also need to be able to audit key usage. Which approach should they take?

⚠ Common exam trap

The trap here is assuming that organization policy constraints automatically apply a specific CMEK, when they only enforce that some CMEK is used.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Create a Cloud KMS key with a rotation period of 90 days, grant the Cloud Storage service account encrypt/decrypt permissions on the key, and configure the bucket to use that key as the default encryption key.

Cloud KMS provides automatic key rotation and audit logging. By setting a bucket default key, all objects are encrypted with the CMEK. Granting the Cloud Storage service account encrypt/decrypt permissions is required for the bucket to use the key. This approach meets encryption, rotation, and auditing requirements with minimal overhead.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Use a Cloud HSM key with a rotation period of 90 days, and configure the bucket with a retention policy that enforces encryption.

    Why it's wrong here

    Cloud HSM keys can be rotated, but a bucket retention policy does not enforce encryption; it only prevents object deletion or modification. This option does not ensure the bucket uses the CMEK. Additionally, Cloud HSM is for hardware-backed keys, which may be overkill and not required by the scenario.

  • ✗

    Use Customer-Supplied Encryption Keys (CSEK) with a 90-day rotation managed by the application, and enable Cloud Audit Logs for Cloud Storage.

    Why it's wrong here

    CSEK are managed by the customer and not stored in Cloud KMS; rotation must be handled manually or by the application. This adds significant operational overhead and does not provide automatic rotation. Cloud Audit Logs for Cloud Storage log API calls but do not audit key usage as Cloud KMS does.

  • ✓

    Create a Cloud KMS key with a rotation period of 90 days, grant the Cloud Storage service account encrypt/decrypt permissions on the key, and configure the bucket to use that key as the default encryption key.

    Why this is correct

    Cloud KMS supports automatic key rotation, which can be set to 90 days. Granting the Cloud Storage service account permissions on the key allows the bucket to use it for encryption. Setting the bucket default key ensures all objects are encrypted with the CMEK. Cloud KMS audit logs capture key usage, meeting the auditing requirement.

  • ✗

    Create a Cloud KMS key with a rotation period of 90 days, and use an organization policy constraint to require CMEK on all Cloud Storage buckets.

    Why it's wrong here

    An organization policy constraint can require CMEK, but it does not automatically apply a specific key to a bucket. The bucket must still be configured to use the key. This option lacks the necessary bucket-level configuration and permissions for the Cloud Storage service account.

About these practice questions

Courseiva writes every PCA question from scratch — 807 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Google Cloud exam blueprint

This PCA practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCA exam.