How to Secure GCS Buckets for Strict Compliance?
You work for an organization that handles sensitive customer data. You must secure a series of Google Cloud Storage buckets housing this data and meet these requirements: • Multiple teams need varying access levels (some read-only, some read-write). • Data must be protected in storage and at rest. • It's critical to track file changes and audit access for compliance purposes. • For compliance purposes, the organization must have control over the encryption keys. What should you do?
Community Votes
100% of anonymous learners picked answer C. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
Tests the intersection of encryption key management and access auditing, with the common trap being confusion between Google-managed keys and customer-controlled keys (CSEK/CMEK).
This question tests securing Google Cloud Storage buckets using customer-supplied encryption keys (CSEK), predefined IAM roles, and audit logging. It establishes that combining CSEK with Cloud Audit Logs and Object Versioning satisfies strict compliance and key-control requirements.
Selecting option B or A because they mention versioning and logs, but overlooking the explicit requirement for organizational control over encryption keys, which necessitates CSEK.
Community Discussion (3 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
Option C directly addresses every requirement by pairing predefined IAM roles with the principle of least privilege, using Customer-Supplied Encryption Keys (CSEK) to ensure the organization retains full control over encryption keys, and enabling both Object Versioning and Cloud Audit Logs for comprehensive change tracking and compliance auditing. TLS encryption further secures data in transit, completing the defense-in-depth strategy required for sensitive customer data.Why the Other Options Are Wrong
Option A relies on Google-managed server-side encryption without granting key control, and uses generic Cloud Monitoring instead of specialized Cloud Audit Logs for compliance. Option B defaults to legacy ACLs rather than modern IAM roles and fails to specify customer-controlled keys. Option D unnecessarily introduces third-party encryption tools and relies on network logs, which cannot provide the granular object-level access auditing mandated by the scenario.Community Comment Notes
The community overwhelmingly supports this choice, with learners consistently highlighting that CSEK is the deciding factor for regulatory key management. As KLei noted, utilizing CSEK ensures the organization "maintains control over the encryption keys," which directly satisfies the compliance mandate. Additional feedback emphasizes that combining tailored IAM roles with Cloud Audit Logs perfectly aligns with least-privilege principles while avoiding the complexity of third-party solutions.Official Reference
Exam Strategy
Always map explicit compliance phrases like “control over encryption keys” directly to CSEK or CMEK in GCP, and pair them with Cloud Audit Logs for any access-tracking requirement. Avoid legacy ACLs or third-party tools when native IAM and managed services fully satisfy the prompt.
Frequently Asked Questions
Why not use Google-managed encryption keys here?
Google-managed keys default to automatic encryption where Google holds the keys, violating the explicit requirement for organizational control over encryption keys for compliance.
Why is Cloud Audit Logs preferred over Cloud Monitoring?
Cloud Audit Logs provides immutable, granular records of administrative and data-access events required for compliance auditing, whereas Cloud Monitoring focuses on metrics and alerting.