mediumMultiple ChoiceObjective-mapped
PCSE Practice Question: A healthcare organization must ensure that only…
A healthcare organization must ensure that only authorized personnel can access Protected Health Information (PHI) stored in Cloud Storage. They need to enforce encryption at rest and control access based on data classification. Which combination of Google Cloud services should they use?
⚠ Common exam trap
Google Cloud often tests the distinction between encryption key management (CMEK vs. CSEK) and access control mechanisms (VPC Service Controls vs. IAM), where candidates mistakenly choose options that address only one requirement or confuse data inspection (DLP) with access enforcement.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use customer-managed encryption keys (CMEK) with Cloud KMS and VPC Service Controls.
It combines customer-managed encryption keys (CMEK) with Cloud KMS to enforce encryption at rest using keys controlled by the organization, and VPC Service Controls to restrict data access based on data classification by creating a security perimeter around Cloud Storage. This ensures that only authorized personnel within the defined perimeter can access PHI, meeting both encryption and access control requirements.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Use customer-supplied encryption keys (CSEK) and Cloud Audit Logs.
Why it's wrong here
CSEK shifts key management to the customer and does not provide network-level controls.
- ✗
Use Cloud HSM for key management and Cloud DLP to inspect data.
Why it's wrong here
Cloud DLP is for classification and de-identification, not for access control perimeters.
- ✗
Enable Access Transparency and use Organization Policies to restrict resource locations.
Why it's wrong here
Access Transparency logs but does not enforce access controls.
- ✓
Use customer-managed encryption keys (CMEK) with Cloud KMS and VPC Service Controls.
Why this is correct
CMEK provides key control; VPC Service Controls prevent data exfiltration beyond the perimeter.
Go deeper
Related to this question
About these practice questions
One of 960 original PCSE practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PCSE practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCSE exam.