Courseiva
Ensuring Data ProtectionmediumMultiple ChoiceObjective-mapped

PCSE Ensuring Data Protection Practice Question

A company wants to enforce that all Compute Engine disk encryption uses keys managed by their own HSM on-premises, with keys provided per API call. Which encryption type should they choose when creating a persistent disk?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Customer-supplied encryption (CSEK)

CSEK (Customer-Supplied Encryption Keys) allows you to provide your own key with each API call, and Google never stores the key. This is appropriate for on-premises HSM integration.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Google-managed encryption (GMEK)

    Why it's wrong here

    Google manages keys.

  • Cloud HSM-backed keys

    Why it's wrong here

    Cloud HSM is Google's managed HSM; keys are stored in Google's HSM.

  • Customer-supplied encryption (CSEK)

    Why this is correct

    Keys are provided per API call; Google does not store them.

  • Customer-managed encryption (CMEK) with Cloud KMS

    Why it's wrong here

    Keys are stored in Cloud KMS, not on-premises HSM.

About these practice questions

Courseiva writes every PCSE question from scratch — 960 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PCSE practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCSE exam.