Courseiva

Google PCA Design for security and compliance Practice Question

A retail company is building a new application on Google Cloud. The security team requires that all data at rest be encrypted with keys the company manages, that key usage be auditable, and that the application on Compute Engine never store long-lived credentials on disk. The architect is selecting controls for the design. (Choose two.)

⚠ Common exam trap

The trap here is assuming that storing a service account key in Secret Manager makes it acceptable, when the credential is still long-lived and still lands on the instance.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Create a Cloud KMS key ring in the same region as the data and use a customer-managed encryption key (CMEK) to encrypt the disks and databases.

The two requirements are company-controlled encryption keys and no long-lived credentials on the instances. Customer-managed encryption keys in Cloud KMS satisfy the first, with audit logging of key use built in. Attaching a service account and pulling short-lived tokens from the metadata server satisfies the second, because the workload never needs a downloaded key file. Together they cover the mandated controls without adding an external key manager dependency.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Enable Cloud External Key Manager with a third-party provider to hold the root key material for all disks and databases.

    Why it's wrong here

    Cloud External Key Manager keeps key material in an external key manager, which gives strong control but adds an external dependency and operational complexity that this scenario does not require. It is typically chosen for sovereignty or separation-of-control mandates, not simply for company-managed keys. The scenario can be met with CMEK in Cloud KMS, so introducing an external key manager is unnecessary here.

  • ✗

    Use Google-managed encryption keys for the disks and rely on Cloud Audit Logs to record who accessed the data.

    Why it's wrong here

    Google-managed keys remove the company's control over key rotation and revocation, so they fail the requirement that the company manage the keys. Audit logs record access to the data but do not provide cryptographic key management. This option addresses logging but not the key custody requirement, and the two requirements must both be satisfied by the design.

  • ✗

    Store a service account key JSON file in Secret Manager and mount it into the instance at boot through a startup script.

    Why it's wrong here

    This still creates a long-lived service account key, which directly violates the requirement that no long-lived credentials be stored on disk. Even though the file lives in Secret Manager, mounting it onto the instance exposes it to anyone who can read the instance filesystem. Secret Manager is useful for application secrets, but it should not be used to distribute service account keys that the metadata server can replace.

  • ✓

    Create a Cloud KMS key ring in the same region as the data and use a customer-managed encryption key (CMEK) to encrypt the disks and databases.

    Why this is correct

    CMEK lets the company own the key lifecycle and rotate or disable keys on its own schedule, which satisfies the requirement that the company manage the keys. Cloud KMS records key usage in Cloud Audit Logs, so every wrap and unwrap operation is attributable. Placing the key ring in the same region as the data also keeps the encryption path local and reduces latency for the data services using the key.

  • ✓

    Attach a service account to the Compute Engine instances and use the metadata server to obtain short-lived access tokens for Google Cloud APIs.

    Why this is correct

    Workloads on Compute Engine can obtain OAuth tokens from the metadata server using the attached service account, so no service account key file is written to disk. The tokens are short-lived and automatically refreshed, which removes the long-lived credential risk the security team wants to eliminate. The service account's IAM roles then determine exactly which APIs the instance can call.

About these practice questions

One of 807 original PCA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Google Cloud exam blueprint

This PCA practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCA exam.