Courseiva
Storing the Data →mediumMultiple Choice

PDE Storing the Data Practice Question

A company stores sensitive data in Cloud Storage and must ensure that data is encrypted at rest with keys that they control and can rotate on demand. They also need to audit key usage and revoke access immediately if a key is compromised. Which Cloud Storage encryption option should they use?

⚠ Common exam trap

The trap here is assuming that customer-supplied encryption keys give the same integrated key management, rotation, and audit capabilities as CMEK, when CSEK keys are not stored or managed by Google Cloud.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Customer-managed encryption keys (CMEK) with Cloud KMS

Customer-managed encryption keys (CMEK) with Cloud KMS allow the company to control and rotate keys, audit key usage through Cloud KMS audit logs, and revoke access by disabling or destroying the key. This satisfies the requirements for customer-controlled encryption, on-demand rotation, and immediate revocation for sensitive Cloud Storage data.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Google-managed encryption keys

    Why it's wrong here

    Google-managed encryption keys are the default and encrypt data at rest, but the company does not control the keys, cannot rotate them on demand, and cannot revoke access independently. This does not meet the requirement for customer-controlled keys with audit and immediate revocation.

  • ✗

    Customer-supplied encryption keys (CSEK)

    Why it's wrong here

    CSEK allows customers to provide their own encryption keys, but Google does not store them, so key rotation and auditing are entirely the customer's responsibility. Immediate revocation is possible only by deleting the key, but there is no integrated audit of key usage, making it less suitable for the stated requirements.

  • ✗

    Client-side encryption before uploading to Cloud Storage

    Why it's wrong here

    Client-side encryption encrypts data before it reaches Cloud Storage, giving the company full control, but it does not provide integrated key management, rotation, or audit logs in Google Cloud. The company would need to build and manage its own key infrastructure, which adds complexity and does not leverage Cloud KMS audit capabilities.

  • ✓

    Customer-managed encryption keys (CMEK) with Cloud KMS

    Why this is correct

    CMEK with Cloud KMS lets the company create, rotate, and manage keys in Cloud KMS, and Cloud Storage uses these keys to encrypt data at rest. Cloud KMS provides audit logs for key usage and allows immediate revocation by disabling or destroying the key, meeting all requirements for control, audit, and revocation.

About these practice questions

One of 747 original PDE practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Google Cloud exam blueprint

This PDE practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PDE exam.