Google PCA Practice Question: Analysing and Optimising Technical and Business Processes
Your company is designing a new application on Google Cloud. The security team requires that all data at rest be encrypted with customer-managed encryption keys (CMEK) and that access to these keys be audited. You need to implement a solution that meets these requirements. (Choose two.)
⚠ Common exam trap
Candidates often confuse customer-supplied encryption keys (CSEK) with customer-managed encryption keys (CMEK); CSEK does not provide Cloud KMS auditing.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use Cloud KMS to create a key ring and crypto key, and grant the Cloud KMS CryptoKey Encrypter/Decrypter role to the service account used by the application.
Using Cloud KMS to create and manage CMEK, and granting the application's service account the CryptoKey Encrypter/Decrypter role, ensures data is encrypted with customer-managed keys. Enabling Cloud Audit Logs for Cloud KMS and exporting them to a central project provides the required auditing of key access. Together, these meet the security requirements.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Use Cloud KMS to create a key ring and crypto key, and grant the Cloud KMS CryptoKey Encrypter/Decrypter role to the service account used by the application.
Why this is correct
Cloud KMS allows you to create and manage customer-managed encryption keys (CMEK). By granting the appropriate IAM role to the service account, the application can use the key to encrypt and decrypt data. This meets the requirement for CMEK. Additionally, Cloud KMS integrates with Cloud Audit Logs to track key usage, satisfying the auditing requirement.
- ✗
Enable VPC Service Controls to restrict access to Cloud KMS resources.
Why it's wrong here
VPC Service Controls help mitigate data exfiltration risks by creating a service perimeter around Google Cloud resources. While it can restrict access to Cloud KMS, it does not provide encryption with CMEK or audit key access. It is a complementary security control but does not fulfill the core requirements of CMEK encryption and key access auditing.
- ✗
Use customer-supplied encryption keys (CSEK) for all Google Cloud services that support them.
Why it's wrong here
Customer-supplied encryption keys (CSEK) allow you to provide your own keys, but they are not managed by Cloud KMS and do not provide the same auditing capabilities. CSEK keys are not stored in Cloud KMS, so access to them cannot be audited through Cloud Audit Logs. This does not meet the requirement for audited key access, and it also places key management burden on the customer.
- ✓
Enable Cloud Audit Logs for Cloud KMS and configure log sinks to export logs to a central logging project.
Why this is correct
Cloud Audit Logs for Cloud KMS record all key operations, including encryption and decryption requests. By enabling audit logs and exporting them to a central project, you can audit access to the keys. This is essential for meeting the security requirement. Together with Cloud KMS, this provides the necessary auditing capability.
- ✗
Configure default encryption at rest using Google-managed encryption keys for all services.
Why it's wrong here
Google-managed encryption keys are the default and provide encryption at rest, but they do not meet the requirement for customer-managed keys. The security team specifically requires CMEK, which gives the customer control over key rotation and revocation. Google-managed keys do not offer the same level of control or auditing specific to customer key usage.
Go deeper
Related to this question
Learn chapter
Cloud SQL and Managed Data Stores
Key term
Data
Data is raw, unprocessed information, like numbers, words, or measurements, that can be stored, processed, and analyzed by computers.
Key term
Project
A project is a temporary endeavor with a defined beginning and end, undertaken to create a unique product, service, or result, managed through specific processes in IT environments.
About these practice questions
Courseiva writes every PCA question from scratch — 807 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Google Cloud exam blueprint
This PCA practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCA exam.