PDE Storing the Data Practice Question
A healthcare company stores patient records in a Cloud Storage bucket that must remain in a specific region for data residency. The security team requires that all data be encrypted with keys the company controls and can rotate, and that access to the keys be auditable. The company also wants to avoid managing key material on-premises. Which approach should the data engineer choose?
⚠ Common exam trap
The trap here is equating default Google-managed encryption with customer-controlled keys, when only CMEK provides rotation and auditable key ownership.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use Customer-Managed Encryption Keys in Cloud KMS with a key ring in the required region.
Customer-Managed Encryption Keys in Cloud KMS give the company ownership and rotation control while Google operates the key infrastructure, and a regional key ring aligns key storage with the data residency requirement. Cloud KMS also writes key usage to audit logs. Default encryption, customer-supplied keys, and external key managers either remove control or push key management outside Google Cloud.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Use Customer-Managed Encryption Keys in Cloud KMS with a key ring in the required region.
Why this is correct
CMEK in Cloud KMS lets the company own, rotate, and disable keys while Google manages the underlying infrastructure, satisfying the no-on-premises requirement. A regional key ring keeps key material aligned with the data residency constraint, and Cloud KMS logs key operations to Cloud Audit Logs for auditability. This meets all stated requirements.
- ✗
Use Customer-Supplied Encryption Keys and store the key material in a local secrets file.
Why it's wrong here
Customer-Supplied Encryption Keys require the company to manage and supply raw key material on every request, which contradicts avoiding on-premises key management. Storing keys in a local file is insecure and hard to rotate or audit. This adds operational burden without the managed rotation and audit trail the company needs.
- ✗
Use Google-managed encryption keys and rely on Google's default encryption for the bucket.
Why it's wrong here
Google-managed keys encrypt data at rest by default, but the company does not control the keys, cannot rotate them on its own schedule, and cannot independently audit key usage. This fails the requirement for customer-controlled, rotatable, auditable keys. It is the weakest option for the stated compliance needs.
- ✗
Use Cloud External Key Manager to connect to a third-party external key management system.
Why it's wrong here
Cloud External Key Manager lets you use keys from a supported external key management system, but that reintroduces external key infrastructure the company wants to avoid managing. It adds complexity around availability and latency. While it offers control, it does not satisfy the goal of avoiding managing key material outside Google Cloud.
Go deeper
Related to this question
About these practice questions
One of 747 original PDE practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Google Cloud exam blueprint
This PDE practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PDE exam.