Google Cloud Physical Security and Data Protection

An organization is concerned about the unlikely event that Google Cloud infrastructure is physically accessed by someone with malicious intent. How is data protected in Google Cloud?

  1. Data is immediately deleted whenever an intrusion is detected.
  2. Data is stored on quantum computers with unbreakable encryption.
  3. Data is stored using robust encryption. Source Reference Answer
  4. Data is stored in random locations around the world to prevent it being found.

Community Votes

C
100%

100% of anonymous learners picked answer C. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

The exam tests understanding of defense-in-depth strategies, specifically highlighting that encryption renders physical access useless to attackers without keys.

This question addresses how Google Cloud protects data against physical infrastructure breaches, establishing that robust encryption is the primary defense mechanism.

Learners may incorrectly choose option D, assuming geographic distribution prevents physical discovery, but data centers are known locations, making encryption the only reliable protection against physical theft.

Community Discussion (3 comments)

joshnort 👍 1 Selected: C
C. Data is stored using robust encryption. Google Cloud uses robust encryption mechanisms to protect data both at rest and in transit: - Data at rest: Google Cloud encrypts stored data using AES-256 encryption or stronger, ensuring that even if someone physically accesses the infrastructure, the data is unreadable without the proper encryption keys. - Data in transit: Data is encrypted when it moves between systems, ensuring security even during transfer. - Key management: Google manages encryption keys securely, and organizations also have the option to manage their own keys using services like Cloud Key Management or Cloud HSM (Hardware Security Module)
asimawan222 👍 2 Selected: C
Data at rest is encrypted by default
Vivek007 👍 4
C: Robust Encryption: Google Cloud uses multiple layers of encryption to protect data at rest and in transit. This means that even if someone were to physically access the hardware, the data stored would still

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

Correct answer: C — Data is stored using robust encryption. Google Cloud employs a comprehensive encryption strategy for data at rest (using AES-256) and in transit. This ensures that even if an attacker physically accesses the storage hardware or hard drives, they cannot read the data without the corresponding cryptographic keys, which are managed separately.

Why the Other Options Are Wrong

Option A is incorrect because immediate deletion upon intrusion detection is not a standard operational practice; it would lead to catastrophic data loss and is technically unfeasible for all services instantly. Option B is incorrect as Google Cloud does not currently use quantum computers for general customer data storage, nor is there such a thing as 'unbreakable' encryption in current technology. Option D is incorrect because while data is distributed globally for redundancy, the physical locations of data centers are public knowledge, so random placement does not prevent malicious actors from finding them.

Community Comment Notes

Community consensus strongly supports option C. As user Vivek007 noted, Google uses multiple layers of encryption to protect data at rest and in transit, ensuring unreadability without keys. User asimawan222 reinforced this by stating that data at rest is encrypted by default. User joshnort provided detailed context on AES-256 encryption, confirming that physical access alone is insufficient without proper encryption keys.

Official Reference

Exam Strategy

When a cloud security question mentions physical access or hardware compromise, immediately look for an encryption-related answer. Remember that robust encryption is the standard last line of defense for data at rest, and avoid distractors that imply reactive deletion, exotic technologies, or random data placement.

Related Analysis

Practice All CDL Questions

Access 84 questions with complete answers and detailed explanations.

View Full CDL Practice Test →

← Back to CDL Study Guide