Courseiva
Storing the Data →hardMultiple Choice

PDE Storing the Data Practice Question

A financial services company must retain trade records for seven years in Cloud Storage. Regulators require that no object can be deleted or overwritten before its retention period expires, even by project owners, and that the policy cannot be removed. The company also needs to prove compliance during audits. Which combination of controls should they implement?

⚠ Common exam trap

Candidates often confuse encryption key control or lifecycle rules with immutability, when only a locked retention policy prevents deletion and modification for a fixed period.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Set a bucket retention policy and lock it, then upload objects with a retention period covering seven years.

A locked bucket retention policy enforces WORM semantics: objects cannot be deleted or overwritten until their retention period elapses, and the lock prevents removal or reduction of the policy. Uploading records with a seven-year retention period satisfies the regulatory timeline and creates auditable proof. Other controls either can be changed, do not block deletion, or address confidentiality rather than immutability.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Enable Object Versioning and apply an Organization Policy that denies storage.objects.delete for all principals.

    Why it's wrong here

    Object Versioning preserves older generations but does not prevent deletion of the live object or of specific generations, and an Organization Policy denying delete can be changed by an organization administrator. It also does not provide the immutable, time-based guarantee regulators require. This combination lacks the tamper-proof retention that a locked retention policy provides, so it fails the audit requirement.

  • ✗

    Configure a lifecycle rule that transitions objects to Archive storage after 30 days and deletes them after seven years.

    Why it's wrong here

    Lifecycle rules automate storage class changes and deletion, but they do not prevent manual or accidental deletion before seven years. They also can be modified or removed by anyone with bucket permissions. This approach reduces cost but does not deliver immutable retention or audit-proof compliance, so it does not meet the regulatory requirement.

  • ✗

    Use Customer-Managed Encryption Keys in Cloud KMS and revoke key access after each upload.

    Why it's wrong here

    Customer-managed keys control who can decrypt data, but revoking key access makes data unreadable rather than preventing deletion. An attacker or administrator could still delete the ciphertext objects, and key destruction is not the same as retention enforcement. This does not provide the time-bound immutability regulators demand, so it is not a valid compliance control here.

  • ✓

    Set a bucket retention policy and lock it, then upload objects with a retention period covering seven years.

    Why this is correct

    A bucket retention policy prevents deletion or replacement of objects until their retention period expires, and once the policy is locked it cannot be removed or shortened. This provides the WORM behavior regulators require and produces audit evidence. Applying it to the bucket and setting object retention for seven years ensures every trade record is protected for the mandated duration, even from project owners.

About these practice questions

This PDE question is part of Courseiva's 747-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Google Cloud exam blueprint

This PDE practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PDE exam.