Google PCA Manage and provision cloud infrastructure Practice Question
A healthcare company stores sensitive patient data in Cloud Storage buckets. The company must ensure that data is encrypted at rest with keys that are automatically rotated every 90 days and that the keys are managed by the company itself, not by Google. The company also needs to maintain full control over key lifecycle and access policies. Which encryption option should the architect recommend?
⚠ Common exam trap
Candidates often confuse customer-managed encryption keys (CMEK) with customer-supplied encryption keys (CSEK); CSEK are not stored in Cloud KMS and do not support automatic rotation.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Customer-managed encryption keys (CMEK) using Cloud KMS with a 90-day rotation schedule.
Customer-managed encryption keys (CMEK) in Cloud KMS allow the healthcare company to manage its own encryption keys, set a 90-day rotation schedule, and control access via IAM. This satisfies the requirements for encryption at rest, automatic key rotation, and full control over key lifecycle. Other options either do not provide self-management or lack automatic rotation.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Cloud External Key Manager (Cloud EKM) with keys stored in a third-party HSM.
Why it's wrong here
Cloud EKM allows the use of externally managed keys, but it requires integration with a supported external key management system, which adds complexity. While it provides control, the scenario does not specify an external HSM requirement. CMEK with Cloud KMS is simpler and directly meets the need for self-managed keys with automatic rotation and IAM policies.
- ✗
Google-managed encryption keys (GMEK) with default encryption.
Why it's wrong here
Google-managed encryption keys are fully managed by Google, including key rotation and lifecycle. The company does not have control over key rotation schedules or access policies, which violates the requirement for self-managed keys and full control. GMEK is the default encryption for Cloud Storage and requires no configuration, but it does not meet the compliance and control needs of this scenario.
- ✓
Customer-managed encryption keys (CMEK) using Cloud KMS with a 90-day rotation schedule.
Why this is correct
Customer-managed encryption keys in Cloud KMS allow the company to create and manage keys, set rotation schedules (e.g., every 90 days), and define access policies via IAM. CMEK integrates with Cloud Storage to encrypt data at rest, and the company retains full control over key lifecycle. This meets all requirements: encryption at rest, automatic rotation, and self-management.
- ✗
Customer-supplied encryption keys (CSEK) provided with each request.
Why it's wrong here
Customer-supplied encryption keys are provided by the client with each request and are not stored in Cloud KMS. The company would need to manage rotation manually and ensure keys are available for every access, which is operationally complex and lacks automatic rotation. CSEK does not provide the centralized key management and access policies required for full control and compliance.
Go deeper
Related to this question
Learn chapter
IAM Policies, Service Accounts, and Auditing
Key term
Least privilege
Least privilege is a security principle that means giving users, systems, or programs only the minimum permissions they need to do their job and nothing more.
Key term
KMS
KMS (Key Management Service) is a Microsoft technology that automates volume licensing activation for Windows and Office products within an organization's network.
About these practice questions
One of 807 original PCA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Google Cloud exam blueprint
This PCA practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCA exam.