Courseiva

Google PCA Design for security and compliance Practice Question

A small company wants to store sensitive files in Cloud Storage and ensure they are encrypted with a key that they control and rotate automatically every 90 days. They are currently using the default encryption provided by Google Cloud. They need a solution that is easy to manage and does not require manual key rotation. What should they do?

⚠ Common exam trap

It's easy for candidates to confuse CMEK (customer-managed, automatic rotation) with CSEK (customer-supplied, manual rotation) or assume default encryption already meets the control requirement, but the question explicitly demands customer-controlled keys with automatic rotation.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Create a Cloud KMS key ring and key with CMEK, set a rotation period of 90 days, and configure the bucket to use that key.

Customer-Managed Encryption Keys (CMEK) via Cloud KMS allow the company to control the key while leveraging automatic rotation. By creating a key ring and key with a 90-day rotation period, and configuring the Cloud Storage bucket to use that key, the company meets the requirement for automated rotation without manual intervention. This solution is easy to manage and integrates natively with Cloud Storage, avoiding the complexity of external encryption or scripting.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Use Cloud HSM to generate a key and handle encryption outside of Cloud Storage.

    Why it's wrong here

    Cloud HSM generates and stores keys but does not integrate with Cloud Storage's envelope encryption, so objects would not be encrypted under a customer-managed key with automatic 90-day rotation. It suits applications performing cryptographic operations directly, not storage-level CMEK.

  • ✓

    Create a Cloud KMS key ring and key with CMEK, set a rotation period of 90 days, and configure the bucket to use that key.

    Why this is correct

    CMEK with a Cloud KMS key gives the company sole control of the encryption key, and configuring a 90-day rotation period automates rotation without manual intervention. The bucket references that key, replacing Google's default encryption, which offers no customer-controlled rotation.

  • ✗

    Use Customer-Supplied Encryption Keys (CSEK) and write a script to rotate the key every 90 days.

    Why it's wrong here

    CSEKs are supplied per request and never stored by Google, so rotation requires re-encrypting every object manually via script, contradicting the automatic 90-day rotation requirement. It is tempting because CSEKs give full key control, but that control comes with manual operational burden.

  • ✗

    Continue using default encryption as it is automatically rotated by Google.

    Why it's wrong here

    Google-managed default encryption rotates keys automatically, but the customer neither controls nor sees those keys, failing the requirement to hold and manage their own key. It is tempting because it is effortless and already active, yet it offers no customer-controlled key material.

About these practice questions

One of 807 original PCA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PCA practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCA exam.