Google PCA Design for security and compliance Practice Question
A retail company is building a new application on Google Cloud. The security team requires that all data at rest be encrypted with keys the company manages, that key usage be auditable, and that the application on Compute Engine never store long-lived credentials on disk. The architect is selecting controls for the design. (Choose two.)
⚠ Common exam trap
The trap here is assuming that storing a service account key in Secret Manager makes it acceptable, when the credential is still long-lived and still lands on the instance.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create a Cloud KMS key ring in the same region as the data and use a customer-managed encryption key (CMEK) to encrypt the disks and databases.
The two requirements are company-controlled encryption keys and no long-lived credentials on the instances. Customer-managed encryption keys in Cloud KMS satisfy the first, with audit logging of key use built in. Attaching a service account and pulling short-lived tokens from the metadata server satisfies the second, because the workload never needs a downloaded key file. Together they cover the mandated controls without adding an external key manager dependency.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Enable Cloud External Key Manager with a third-party provider to hold the root key material for all disks and databases.
Why it's wrong here
Cloud External Key Manager keeps key material in an external key manager, which gives strong control but adds an external dependency and operational complexity that this scenario does not require. It is typically chosen for sovereignty or separation-of-control mandates, not simply for company-managed keys. The scenario can be met with CMEK in Cloud KMS, so introducing an external key manager is unnecessary here.
- ✗
Use Google-managed encryption keys for the disks and rely on Cloud Audit Logs to record who accessed the data.
Why it's wrong here
Google-managed keys remove the company's control over key rotation and revocation, so they fail the requirement that the company manage the keys. Audit logs record access to the data but do not provide cryptographic key management. This option addresses logging but not the key custody requirement, and the two requirements must both be satisfied by the design.
- ✗
Store a service account key JSON file in Secret Manager and mount it into the instance at boot through a startup script.
Why it's wrong here
This still creates a long-lived service account key, which directly violates the requirement that no long-lived credentials be stored on disk. Even though the file lives in Secret Manager, mounting it onto the instance exposes it to anyone who can read the instance filesystem. Secret Manager is useful for application secrets, but it should not be used to distribute service account keys that the metadata server can replace.
- ✓
Create a Cloud KMS key ring in the same region as the data and use a customer-managed encryption key (CMEK) to encrypt the disks and databases.
Why this is correct
CMEK lets the company own the key lifecycle and rotate or disable keys on its own schedule, which satisfies the requirement that the company manage the keys. Cloud KMS records key usage in Cloud Audit Logs, so every wrap and unwrap operation is attributable. Placing the key ring in the same region as the data also keeps the encryption path local and reduces latency for the data services using the key.
- ✓
Attach a service account to the Compute Engine instances and use the metadata server to obtain short-lived access tokens for Google Cloud APIs.
Why this is correct
Workloads on Compute Engine can obtain OAuth tokens from the metadata server using the attached service account, so no service account key file is written to disk. The tokens are short-lived and automatically refreshed, which removes the long-lived credential risk the security team wants to eliminate. The service account's IAM roles then determine exactly which APIs the instance can call.
Go deeper
Related to this question
Learn chapter
Security Best Practices and Compliance
Key term
Compute Engine
Compute Engine is Google Cloud's Infrastructure-as-a-Service (IaaS) offering that lets you create and run virtual machines on Google's infrastructure.
Key term
Service account
A service account is a special type of account used by an application or a virtual machine, rather than a human user, to authenticate and interact with cloud services and APIs securely.
About these practice questions
One of 807 original PCA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Google Cloud exam blueprint
This PCA practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCA exam.