Courseiva
mediumMultiple Choice

PDE Practice Question: A team is designing a data lake on Google Cloud…

A team is designing a data lake on Google Cloud using Cloud Storage and BigQuery. They need to ensure that sensitive data (e.g., PII) is encrypted at rest and have the ability to audit access. Which approach meets these requirements?

⚠ Common exam trap

Google Cloud often tests the distinction between encryption key management (CMEK vs. CSEK vs. Default) and security controls (VPC Service Controls vs. Audit Logs), leading candidates to conflate network perimeter controls with audit capabilities.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Use Customer-Managed Encryption Keys (CMEK) and enable Cloud Audit Logs.

Customer-Managed Encryption Keys (CMEK) allow the team to control and manage the encryption keys used to protect data at rest in Cloud Storage and BigQuery, while enabling Cloud Audit Logs provides the necessary audit trail for access to both the data and the keys. This combination directly satisfies the requirements for encryption at rest and auditability.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Use Customer-Managed Encryption Keys (CMEK) and enable VPC Service Controls.

    Why it's wrong here

    CMEK encrypts Cloud Storage and BigQuery data at rest under customer-controlled Cloud KMS keys, but VPC Service Controls provide perimeter enforcement, not the access auditing the scenario demands. CMEK is tempting because it satisfies key custody, and would be correct when the sole requirement is customer-managed encryption.

  • ✓

    Use Customer-Managed Encryption Keys (CMEK) and enable Cloud Audit Logs.

    Why this is correct

    CMEK lets the team control and rotate the encryption keys protecting PII at rest, while Cloud Audit Logs record every access to that data. Together they satisfy both the encryption-at-rest and access-auditing requirements for the Cloud Storage and BigQuery data lake.

  • ✗

    Use Default Encryption and enable Data Loss Prevention (DLP) API.

    Why it's wrong here

    Default encryption already encrypts data at rest, so DLP adds classification and inspection but no key control, and Cloud Audit Logs, not DLP, provide the access auditing required. DLP is tempting because it discovers and redacts PII, and would be correct when the requirement is data classification or de-identification.

  • ✗

    Use Customer-Supplied Encryption Keys (CSEK) and enable VPC Service Controls.

    Why it's wrong here

    CSEKs are supplied per request by the client and are unsupported for BigQuery, so they cannot encrypt the whole data lake at rest. They are tempting because they give the customer sole key custody, and would be correct for Cloud Storage objects when external key management is mandated.

About these practice questions

This PDE question is part of Courseiva's 747-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PDE practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PDE exam.