Courseiva

Google PCA Design for security and compliance Practice Question

A retail company is designing a Google Cloud landing zone for a regulated workload. They must ensure that encryption keys for Cloud Storage and BigQuery are generated and stored outside Google's infrastructure, with the ability to revoke access immediately. They also must retain detailed records of who accessed the data and when, for seven years. Which TWO configurations should the architect include? (Choose two.)

⚠ Common exam trap

The trap here is treating Cloud KMS HSM keys or VPC Service Controls as sufficient for external key custody and long-term access auditing, when neither places key material outside Google or produces the required access records.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Use Cloud External Key Manager (Cloud EKM) with an external key manager reachable over the internet or Interconnect

Cloud EKM places key custody in an external manager you operate, letting you revoke keys instantly and keeping key material outside Google, which covers the encryption requirement. Enabling Data Access audit logs and routing them into a locked, seven-year retention bucket creates the immutable access record the regulation demands.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Use Cloud External Key Manager (Cloud EKM) with an external key manager reachable over the internet or Interconnect

    Why this is correct

    Cloud EKM lets Cloud KMS call an external key manager you control, so key material resides outside Google and never enters Google's infrastructure. Revoking the external key immediately renders wrapped data keys unusable, satisfying both the external custody and rapid revocation requirements for Cloud Storage and BigQuery.

  • ✗

    Enable default encryption with Google-managed keys on all storage buckets

    Why it's wrong here

    Google-managed default encryption protects data at rest but keeps key custody entirely with Google and offers no mechanism for customer-initiated revocation. It also does not generate the required access records, so it fails both the external key custody and the seven-year audit logging requirements.

  • ✗

    Configure Cloud KMS with HSM protection level for all customer-managed encryption keys

    Why it's wrong here

    Cloud KMS HSM-backed keys still reside in Google-managed infrastructure and are operated by Google KMS, so they do not meet the requirement that key material be generated and stored outside Google. HSM protection level strengthens key operations but does not place key custody with the customer.

  • ✗

    Enable VPC Service Controls perimeters around the storage and analytics projects

    Why it's wrong here

    VPC Service Controls restrict data movement across a perimeter boundary and mitigate exfiltration, but they neither manage encryption keys nor produce access audit records. They are a complementary network-layer control and do not satisfy the external key custody or the seven-year access-logging requirements on their own.

  • ✓

    Enable Data Access audit logs for Cloud Storage and BigQuery and route them to a log bucket with a seven-year retention lock

    Why this is correct

    Data Access audit logs record reads and writes with the caller identity and timestamp. Routing them to a Cloud Logging bucket configured with a locked retention period of seven years preserves the audit trail immutably, directly fulfilling the seven-year access-record requirement for both services.

About these practice questions

Courseiva writes every PCA question from scratch — 807 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Google Cloud exam blueprint

This PCA practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCA exam.