mediumMultiple ChoiceObjective-mapped
PDE Practice Question: A team is designing a data lake on Google Cloud…
A team is designing a data lake on Google Cloud using Cloud Storage and BigQuery. They need to ensure that sensitive data (e.g., PII) is encrypted at rest and have the ability to audit access. Which approach meets these requirements?
⚠ Common exam trap
Google Cloud often tests the distinction between encryption key management (CMEK vs. CSEK vs. Default) and security controls (VPC Service Controls vs. Audit Logs), leading candidates to conflate network perimeter controls with audit capabilities.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use Customer-Managed Encryption Keys (CMEK) and enable Cloud Audit Logs.
Customer-Managed Encryption Keys (CMEK) allow the team to control and manage the encryption keys used to protect data at rest in Cloud Storage and BigQuery, while enabling Cloud Audit Logs provides the necessary audit trail for access to both the data and the keys. This combination directly satisfies the requirements for encryption at rest and auditability.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Use Customer-Managed Encryption Keys (CMEK) and enable VPC Service Controls.
Why it's wrong here
VPC Service Controls reduce exfiltration risk but do not provide access auditing.
- ✓
Use Customer-Managed Encryption Keys (CMEK) and enable Cloud Audit Logs.
Why this is correct
CMEK provides control over encryption keys, and Cloud Audit Logs record access to data.
- ✗
Use Default Encryption and enable Data Loss Prevention (DLP) API.
Why it's wrong here
Default Encryption does not allow customer control over keys.
- ✗
Use Customer-Supplied Encryption Keys (CSEK) and enable VPC Service Controls.
Why it's wrong here
CSEK requires the customer to supply the key material, which may not be desirable for all scenarios.
Go deeper
Related to this question
About these practice questions
This PDE question is part of Courseiva's 890-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PDE practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PDE exam.