PDE Storing the Data Practice Question
A company wants to build a reporting pipeline where data is collected from IoT devices, stored raw in Cloud Storage, and then processed into BigQuery for analytics. They need to ensure data is encrypted at rest using customer-managed keys. Which THREE steps should they take? (Choose 3 correct options)
⚠ Common exam trap
A common trap is thinking that only one component needs CMEK enabled, but for this data pipeline, both Cloud Storage and BigQuery must be configured to use the same customer-managed key. Another trap is selecting 'Delete the Cloud KMS key after data is loaded' (option A), which is incorrect because it would make data unrecoverable and non-compliant.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Enable CMEK on the Cloud Storage bucket by specifying the KMS key
The scenario requires customer-managed encryption keys (CMEK) for data at rest across Cloud Storage and BigQuery, so the foundational step is option E: create a key ring and key in Cloud Key Management Service, since CMEK always begins with a KMS key ring and a key (or key version) that will be referenced by the services. Option B is correct because enabling CMEK on the Cloud Storage bucket by specifying the KMS key ensures the raw IoT data written to the bucket is encrypted at rest with that customer-managed key rather than a Google-managed key. Option C is correct because configuring the BigQuery dataset to use a CMEK key ensures the processed analytics data stored in BigQuery is also encrypted at rest with the customer-managed key, satisfying the end-to-end requirement. Option A is wrong because deleting the Cloud KMS key after loading would make the encrypted data unrecoverable and break decryption for both Cloud Storage and BigQuery. Option D is wrong because Google-managed encryption keys are the default and do not meet the requirement for customer-managed keys.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Delete the Cloud KMS key after data is loaded to BigQuery
Why it's wrong here
Deleting the Cloud KMS key destroys the key material, making the CMEK-encrypted data permanently unreadable and unrecoverable. Key deletion is a deliberate crypto-shredding action, not a pipeline step. Retaining the key is required so BigQuery can decrypt data at query time; deletion would be the choice only when intentionally destroying all associated data.
- ✓
Enable CMEK on the Cloud Storage bucket by specifying the KMS key
Why this is correct
Specifying a Cloud KMS key on the Cloud Storage bucket enforces customer-managed encryption at rest for the raw IoT data, satisfying the stem's CMEK constraint at the storage layer. Without this, Google-managed keys apply by default, so the raw landing zone would fail the customer-managed key requirement before BigQuery processing begins.
- ✓
Configure the BigQuery dataset to use a CMEK key
Why this is correct
Configuring the BigQuery dataset with a customer-managed encryption key (CMEK) ensures the processed analytics data is encrypted at rest under your own Cloud KMS key, satisfying the stem's customer-managed key requirement for the BigQuery stage of the pipeline.
- ✗
Use Google-managed encryption keys
Why it's wrong here
Google-managed encryption keys are the default at-rest protection and give the customer no control over key rotation, access or revocation, so they fail the customer-managed key requirement. They are the correct choice when the organisation has no key-management obligation and simply wants encryption without operational overhead.
- ✓
Create a key ring and key in Cloud Key Management Service
Why this is correct
Cloud KMS key rings and keys provide the customer-managed encryption keys (CMEK) that satisfy the stem's encryption-at-rest requirement. Creating the key here is the prerequisite step: without a key ring and key, no CMEK configuration can be applied to Cloud Storage buckets or BigQuery datasets.
Go deeper
Related to this question
About these practice questions
One of 747 original PDE practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PDE practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PDE exam.