Google PCA Manage and provision cloud infrastructure Practice Question
Your company is using Cloud Storage to store sensitive customer data. The security team requires that all objects be encrypted with a customer-managed encryption key (CMEK) and that the key be automatically rotated every 90 days. You need to implement this without changing the application code. You have created a Cloud KMS key ring and a key with rotation period set to 90 days. What additional configuration is required?
⚠ Common exam trap
Many candidates think granting the Cloud KMS role to the Cloud Storage service account (Option C) is sufficient, but they overlook the critical step of actually setting the key as the default encryption key on the bucket to enforce automatic encryption.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Set the default encryption key of the Cloud Storage bucket to the Cloud KMS key.
Setting the default encryption key of the Cloud Storage bucket to the Cloud KMS key ensures that all objects written to the bucket are automatically encrypted with that CMEK, without requiring any application code changes. The Cloud KMS key's rotation period of 90 days is already configured, so the key will be rotated automatically, meeting the security team's requirement.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Set a bucket lifecycle rule to transition objects to a different storage class.
Why it's wrong here
Lifecycle rules move objects between storage classes; they do not apply encryption keys to objects. It tempts because lifecycle configuration is a common bucket-level setting, but the requirement is CMEK application. Setting the bucket's default KMS key is what encrypts new objects without code changes.
- ✗
Create a custom customer-supplied encryption key (CSEK) and provide it in each request.
Why it's wrong here
CSEK keys are supplied by the client on every request and are never stored or rotated by Cloud KMS, so the 90-day automatic rotation requirement cannot be met. It is tempting because CSEK gives customer-controlled encryption without code changes, but it suits scenarios demanding externally held keys, not managed rotation.
- ✗
Grant the Cloud KMS CryptoKey Encrypter/Decrypter role to the Cloud Storage service account.
Why it's wrong here
Granting the CryptoKey Encrypter/Decrypter role to the Cloud Storage service account is required for CMEK to function, but the question asks what makes objects use the key by default without code changes. It tempts because permissions are genuinely necessary, yet the missing configuration is the bucket's default KMS key.
- ✓
Set the default encryption key of the Cloud Storage bucket to the Cloud KMS key.
Why this is correct
Setting the bucket's default encryption key to the Cloud KMS key applies CMEK automatically to every newly written object, satisfying the customer-managed key requirement without application changes. Cloud KMS handles the 90-day rotation transparently, since rotation generates new key versions while the key resource name stays constant, so existing object references remain valid.
Go deeper
Related to this question
Learn chapter
Security Best Practices and Compliance
Key term
Cloud storage
Cloud storage is a service that lets you save data on remote servers accessed over the internet instead of on your computer's hard drive.
Key term
KMS
KMS (Key Management Service) is a Microsoft technology that automates volume licensing activation for Windows and Office products within an organization's network.
About these practice questions
Courseiva writes every PCA question from scratch — 807 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PCA practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCA exam.