Courseiva
Ensuring Data ProtectionmediumMultiple ChoiceObjective-mapped

PCSE Ensuring Data Protection Practice Question

A company uses Cloud KMS to manage encryption keys for data at rest. They want to automatically rotate a symmetric key every 90 days. The key is used to encrypt Cloud Storage objects and BigQuery tables. What is the correct approach to achieve automatic rotation?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Set the rotation period on the key to 90 days and ensure the key purpose is ENCRYPT_DECRYPT.

In Cloud KMS, you can set a rotation period on a key. Automatic rotation creates a new key version at the specified interval. The key must have purpose ENCRYPT_DECRYPT for symmetric encryption. Manual rotation is not automatic, and setting a rotation period on key rings is not possible.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Use a Cloud Function to rotate the key every 90 days via the Cloud KMS API.

    Why it's wrong here

    Using a Cloud Function to call the Cloud KMS API for symmetric key rotation is incorrect because Cloud KMS provides native, scheduled automatic rotation directly on the symmetric key resource itself. This built-in service feature handles the rotation schedule without requiring external compute or custom code. Cloud Functions are excellent for custom automation, such as triggering actions *after* a key rotation event, or for managing asymmetric keys which lack native scheduled rotation, making this option tempting for general automation tasks.

  • Set the rotation period on the key to 90 days and ensure the key purpose is ENCRYPT_DECRYPT.

    Why this is correct

    Setting rotation period on the key itself enables automatic rotation. ENCRYPT_DECRYPT is required for symmetric encryption.

  • Create a Cloud Scheduler job to manually rotate the key every 90 days.

    Why it's wrong here

    Manual rotation is not automatic; it requires an external scheduler and extra management.

  • Set the rotation period on the key ring to 90 days.

    Why it's wrong here

    Rotation periods are set on individual keys, not key rings.

Quick reference

Symmetric Encryption Algorithm Comparison

AlgorithmKey SizeBlock SizeStatusNotes
AES-128128-bit128-bitCurrent standardNIST approved; WPA3, TLS
AES-256256-bit128-bitCurrent standardPreferred for sensitive / govt data
3DES112-bit effective64-bitDeprecated (2023)Replaced by AES
DES56-bit64-bitBrokenCracked in < 24 h; never deploy
ChaCha20256-bitStream cipherCurrentTLS 1.3, WireGuard

About these practice questions

This PCSE question is part of Courseiva's 960-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PCSE practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCSE exam.