Courseiva

Google PCA Design for security and compliance Practice Question

A multinational corporation must comply with GDPR and requires that all customer data stored in BigQuery be encrypted using customer-managed encryption keys (CMEK) and that the keys are stored in a specific region. Which combination of steps should they take?

⚠ Common exam trap

A common pitfall is that candidates may confuse Cloud DLP or EKM as valid methods for BigQuery encryption at rest, when only CMEK via Cloud KMS with DDL association meets the specific requirement of regional key storage and customer control.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Create a Cloud KMS key ring and crypto key in the desired region, then associate the BigQuery dataset with the CMEK key using DDL

It directly fulfills the requirement: creating a Cloud KMS key ring and crypto key in the desired region, then associating the BigQuery dataset with that CMEK key using DDL (e.g., `ALTER SCHEMA mydataset SET OPTIONS(kms_key_name='...')`). This ensures that all data at rest in BigQuery is encrypted with a customer-managed key stored in a specific regional location, as mandated by GDPR for data residency and control.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Enable default encryption at rest in BigQuery and use Organization Policies to restrict key location

    Why it's wrong here

    Default encryption uses Google-managed keys, not customer-managed keys, and Organisation Policies constrain resource locations rather than key storage regions. It is tempting as a low-effort compliance baseline when Google-managed encryption and location restrictions satisfy the regulatory requirement.

  • ✓

    Create a Cloud KMS key ring and crypto key in the desired region, then associate the BigQuery dataset with the CMEK key using DDL

    Why this is correct

    Creating the Cloud KMS key ring and crypto key in the required region, then associating the BigQuery dataset with that CMEK key via DDL, satisfies both GDPR constraints: customer-managed keys and regional key residency. BigQuery then encrypts data with that key.

  • ✗

    Create a Cloud HSM key, then use Cloud DLP to automatically encrypt the data before loading into BigQuery

    Why it's wrong here

    Cloud DLP encrypts data before loading, but BigQuery CMEK requires the dataset's encryption configuration to reference a Cloud KMS key, not DLP-transformed ciphertext. It is tempting when de-identifying or tokenising sensitive fields prior to ingestion is the actual compliance goal.

  • ✗

    Use Cloud External Key Manager (EKM) to integrate with an on-premises key management system

    Why it's wrong here

    Cloud EKM sources key material from an external manager, so the keys reside outside Google Cloud rather than in the required region. It is tempting when regulation demands keys be held externally, such as in an on-premises HSM under the organisation's own control.

About these practice questions

One of 807 original PCA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PCA practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCA exam.