For IndividualsFor Educators
ExpertMinds LogoExpertMinds
ExpertMinds

Ace your certifications with Practice Exams and AI assistance.

  • Browse Exams
  • For Educators
  • Blog
  • Privacy Policy
  • Terms of Service
  • Cookie Policy
  • Support
  • AWS SAA Exam Prep
  • PMI PMP Exam Prep
  • CPA Exam Prep
  • GCP PCA Exam Prep

© 2026 TinyHive Labs. Company number 16262776.

    PracticeGCP Professional Cloud ArchitectGCP Professional Cloud Architect Practice Exam 5Question 48
    Medium1 markMultiple Choice
    Subtask 3.1: Security DesignSecurityEncryptionCloud KMSCMEK

    GCP PCA · Question 48 · Security Design

    Your organization is migrating sensitive data to Cloud Storage. The security team dictates that Google must not manage the encryption keys, but they also do not want the operational burden of maintaining their own highly available key servers on-premises. Which TWO actions should you take? (Select TWO)

    Answer options:

    A.

    Use Customer-Managed Encryption Keys (CMEK)

    B.

    Use Customer-Supplied Encryption Keys (CSEK)

    C.

    Create a Key Ring and Key in Cloud KMS

    D.

    Use Google-Managed Encryption Keys (GMEK)

    E.

    Encrypt the data locally using a Python script before uploading

    How to approach this question

    Identify the encryption method that provides control without infrastructure overhead.

    Full Answer

    Use Customer-Managed Encryption Keys (CMEK), Create a Key Ring and Key in Cloud KMS
    Customer-Managed Encryption Keys (CMEK) strike the balance between control and operational overhead. The keys are generated and stored in Google's Cloud Key Management Service (Cloud KMS), so Google handles the high availability. However, the customer retains full cryptographic control over the keys.

    Common mistakes

    Choosing CSEK (B), which forces the customer to build their own key servers.
    Question 47All questionsQuestion 49

    Practice the full GCP Professional Cloud Architect Practice Exam 5

    50 questions · hints · full answers · grading

    Sign up freeTake the exam

    More questions from this exam

    Q01CASE STUDY: TechStream Gaming Overview: Gaming company, 500 employees, $100M revenue. 200 on-prem...HardQ02CASE STUDY: TechStream Gaming Overview: Gaming company, 500 employees, $100M revenue. 200 on-prem...MediumQ03CASE STUDY: TechStream Gaming Overview: Gaming company, 500 employees, $100M revenue. 200 on-prem...MediumQ04CASE STUDY: TechStream Gaming Overview: Gaming company, 500 employees, $100M revenue. 200 on-prem...MediumQ05CASE STUDY: TechStream Gaming Overview: Gaming company, 500 employees, $100M revenue. 200 on-prem...Easy
    View all 50 questions →