Google PCA Design for security and compliance Practice Question
A small company wants to store sensitive files in Cloud Storage and ensure they are encrypted with a key that they control and rotate automatically every 90 days. They are currently using the default encryption provided by Google Cloud. They need a solution that is easy to manage and does not require manual key rotation. What should they do?
⚠ Common exam trap
It's easy for candidates to confuse CMEK (customer-managed, automatic rotation) with CSEK (customer-supplied, manual rotation) or assume default encryption already meets the control requirement, but the question explicitly demands customer-controlled keys with automatic rotation.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create a Cloud KMS key ring and key with CMEK, set a rotation period of 90 days, and configure the bucket to use that key.
Customer-Managed Encryption Keys (CMEK) via Cloud KMS allow the company to control the key while leveraging automatic rotation. By creating a key ring and key with a 90-day rotation period, and configuring the Cloud Storage bucket to use that key, the company meets the requirement for automated rotation without manual intervention. This solution is easy to manage and integrates natively with Cloud Storage, avoiding the complexity of external encryption or scripting.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Use Cloud HSM to generate a key and handle encryption outside of Cloud Storage.
Why it's wrong here
Cloud HSM generates and stores keys but does not integrate with Cloud Storage's envelope encryption, so objects would not be encrypted under a customer-managed key with automatic 90-day rotation. It suits applications performing cryptographic operations directly, not storage-level CMEK.
- ✓
Create a Cloud KMS key ring and key with CMEK, set a rotation period of 90 days, and configure the bucket to use that key.
Why this is correct
CMEK with a Cloud KMS key gives the company sole control of the encryption key, and configuring a 90-day rotation period automates rotation without manual intervention. The bucket references that key, replacing Google's default encryption, which offers no customer-controlled rotation.
- ✗
Use Customer-Supplied Encryption Keys (CSEK) and write a script to rotate the key every 90 days.
Why it's wrong here
CSEKs are supplied per request and never stored by Google, so rotation requires re-encrypting every object manually via script, contradicting the automatic 90-day rotation requirement. It is tempting because CSEKs give full key control, but that control comes with manual operational burden.
- ✗
Continue using default encryption as it is automatically rotated by Google.
Why it's wrong here
Google-managed default encryption rotates keys automatically, but the customer neither controls nor sees those keys, failing the requirement to hold and manage their own key. It is tempting because it is effortless and already active, yet it offers no customer-controlled key material.
Go deeper
Related to this question
Learn chapter
Cloud Storage: Objects and Buckets
Key term
Cloud storage
Cloud storage is a service that lets you save data on remote servers accessed over the internet instead of on your computer's hard drive.
Key term
Cloud KMS
Cloud KMS (Key Management Service) is a cloud-based service that lets you create, manage, and use encryption keys to protect your data at rest and in transit.
About these practice questions
One of 807 original PCA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PCA practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCA exam.