Google PCA Design for security and compliance Practice Question
A retail company is designing a Google Cloud landing zone for a regulated workload. They must ensure that encryption keys for Cloud Storage and BigQuery are generated and stored outside Google's infrastructure, with the ability to revoke access immediately. They also must retain detailed records of who accessed the data and when, for seven years. Which TWO configurations should the architect include? (Choose two.)
⚠ Common exam trap
The trap here is treating Cloud KMS HSM keys or VPC Service Controls as sufficient for external key custody and long-term access auditing, when neither places key material outside Google or produces the required access records.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use Cloud External Key Manager (Cloud EKM) with an external key manager reachable over the internet or Interconnect
Cloud EKM places key custody in an external manager you operate, letting you revoke keys instantly and keeping key material outside Google, which covers the encryption requirement. Enabling Data Access audit logs and routing them into a locked, seven-year retention bucket creates the immutable access record the regulation demands.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Use Cloud External Key Manager (Cloud EKM) with an external key manager reachable over the internet or Interconnect
Why this is correct
Cloud EKM lets Cloud KMS call an external key manager you control, so key material resides outside Google and never enters Google's infrastructure. Revoking the external key immediately renders wrapped data keys unusable, satisfying both the external custody and rapid revocation requirements for Cloud Storage and BigQuery.
- ✗
Enable default encryption with Google-managed keys on all storage buckets
Why it's wrong here
Google-managed default encryption protects data at rest but keeps key custody entirely with Google and offers no mechanism for customer-initiated revocation. It also does not generate the required access records, so it fails both the external key custody and the seven-year audit logging requirements.
- ✗
Configure Cloud KMS with HSM protection level for all customer-managed encryption keys
Why it's wrong here
Cloud KMS HSM-backed keys still reside in Google-managed infrastructure and are operated by Google KMS, so they do not meet the requirement that key material be generated and stored outside Google. HSM protection level strengthens key operations but does not place key custody with the customer.
- ✗
Enable VPC Service Controls perimeters around the storage and analytics projects
Why it's wrong here
VPC Service Controls restrict data movement across a perimeter boundary and mitigate exfiltration, but they neither manage encryption keys nor produce access audit records. They are a complementary network-layer control and do not satisfy the external key custody or the seven-year access-logging requirements on their own.
- ✓
Enable Data Access audit logs for Cloud Storage and BigQuery and route them to a log bucket with a seven-year retention lock
Why this is correct
Data Access audit logs record reads and writes with the caller identity and timestamp. Routing them to a Cloud Logging bucket configured with a locked retention period of seven years preserves the audit trail immutably, directly fulfilling the seven-year access-record requirement for both services.
Go deeper
Related to this question
Learn chapter
Identity and Access Management (IAM)
Key term
Data
Data is raw, unprocessed information, like numbers, words, or measurements, that can be stored, processed, and analyzed by computers.
Key term
BigQuery
BigQuery is a fully managed, serverless data warehouse on Google Cloud that lets you run fast SQL queries on massive datasets without managing any infrastructure.
About these practice questions
Courseiva writes every PCA question from scratch — 807 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Google Cloud exam blueprint
This PCA practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCA exam.