PDE Storing the Data Practice Question
A media company stores final video masters in a Cloud Storage bucket. Regulatory rules require that each object be unalterable for seven years, and the company must be able to prove retention compliance to auditors. Objects are written once and never edited. The data engineer needs the strongest native Cloud Storage control that prevents deletion or overwrite for the required period. What should the engineer configure?
⚠ Common exam trap
Candidates often confuse access control or versioning with true immutability, when only a locked retention policy legally prevents deletion.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
A bucket retention policy with a seven-year retention period and a locked retention policy.
A locked bucket retention policy is the native Cloud Storage feature that enforces immutability for a fixed period and cannot be weakened once locked. It directly satisfies the write-once, provable-retention requirement, whereas versioning, signed URLs, and IAM policies only govern recovery or access. For regulatory retention of final masters, the locked retention policy is the correct control.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
A bucket retention policy with a seven-year retention period and a locked retention policy.
Why this is correct
A bucket retention policy prevents deletion or replacement of objects until the retention period elapses, and locking the policy makes it permanent so it cannot be shortened or removed. This gives the unalterable, provable seven-year guarantee the auditors require, and it is the native Cloud Storage control designed for exactly this write-once retention need.
- ✗
Uniform bucket-level access with IAM roles limited to a single compliance group.
Why it's wrong here
Uniform bucket-level access simplifies permission management by disabling object ACLs, and IAM restricts who can act. However, any principal granted storage.objects.delete can still delete objects, so this is access control, not immutability. It cannot demonstrate to an auditor that the masters were technically unalterable for seven years.
- ✗
Object Versioning on the bucket plus a lifecycle rule to delete noncurrent versions.
Why it's wrong here
Object Versioning preserves prior generations when an object is overwritten or deleted, but any user with permission can still delete the live object and all versions. It is a recovery mechanism, not a retention lock, and a lifecycle rule actively deletes noncurrent versions. It cannot prove to auditors that data was unalterable for seven years.
- ✗
A signed URL with a seven-year expiration that is shared only with the compliance team.
Why it's wrong here
Signed URLs grant temporary access to an object and can be revoked, and the maximum expiration is bounded well below seven years. They control who can read or write, not whether the object can be deleted or overwritten. Sharing a long-lived URL does not create any retention guarantee and would be a security risk.
Go deeper
Related to this question
About these practice questions
Courseiva writes every PDE question from scratch — 747 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Google Cloud exam blueprint
This PDE practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PDE exam.