How to Secure GCS Buckets for Strict Compliance?

Cloud Storage Security
Answer Correct answer: C — Apply predefined IAM roles, use customer-supplied encryption keys (CSEK), enforce TLS, and enable Object Versioning with Cloud Audit Logs.

You work for an organization that handles sensitive customer data. You must secure a series of Google Cloud Storage buckets housing this data and meet these requirements: • Multiple teams need varying access levels (some read-only, some read-write). • Data must be protected in storage and at rest. • It's critical to track file changes and audit access for compliance purposes. • For compliance purposes, the organization must have control over the encryption keys. What should you do?

  1. Create IAM groups for each team and manage permissions at the group level. Employ server-side encryption and Object Versioning by Google Cloud Storage. Configure cloud monitoring tools to alert on anomalous data access patterns.
  2. Set individual permissions for each team and apply access control lists (ACLs) to each bucket and file. Enforce TLS encryption for file transfers. Enable Object Versioning and Cloud Audit Logs for the storage buckets.
  3. Use predefined IAM roles tailored to each team's access needs, such as Storage Object Viewer and Storage Object User. Utilize customer-supplied encryption keys (CSEK) and enforce TLS encryption. Turn on both Object Versioning and Cloud Audit Logs for the storage buckets. Correct Answer
  4. Assign IAM permissions for all teams at the object level. Implement third-party software to encrypt data at rest. Track data access by using network logs.

Community Votes

C
100%

100% of anonymous learners picked answer C. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

Tests the intersection of encryption key management and access auditing, with the common trap being confusion between Google-managed keys and customer-controlled keys (CSEK/CMEK).

This question tests securing Google Cloud Storage buckets using customer-supplied encryption keys (CSEK), predefined IAM roles, and audit logging. It establishes that combining CSEK with Cloud Audit Logs and Object Versioning satisfies strict compliance and key-control requirements.

Selecting option B or A because they mention versioning and logs, but overlooking the explicit requirement for organizational control over encryption keys, which necessitates CSEK.

Community Discussion (3 comments)

Pime13 👍 1 Selected: C
This approach ensures that: Access Control: IAM roles are tailored to each team's needs, providing the principle of least privilege. Data Protection: Customer-supplied encryption keys (CSEK) give your organization control over encryption keys, and TLS encryption protects data in transit. Compliance and Auditing: Object Versioning and Cloud Audit Logs help track file changes and audit access for compliance purposes. https://cloud.google.com/architecture/framework/security/privacy
KLei 👍 2 Selected: C
By utilizing CSEK, your organization maintains control over the encryption keys, which is crucial for compliance purposes.
yokoyan 👍 3 Selected: C
I think it's C.

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

Option C directly addresses every requirement by pairing predefined IAM roles with the principle of least privilege, using Customer-Supplied Encryption Keys (CSEK) to ensure the organization retains full control over encryption keys, and enabling both Object Versioning and Cloud Audit Logs for comprehensive change tracking and compliance auditing. TLS encryption further secures data in transit, completing the defense-in-depth strategy required for sensitive customer data.

Why the Other Options Are Wrong

Option A relies on Google-managed server-side encryption without granting key control, and uses generic Cloud Monitoring instead of specialized Cloud Audit Logs for compliance. Option B defaults to legacy ACLs rather than modern IAM roles and fails to specify customer-controlled keys. Option D unnecessarily introduces third-party encryption tools and relies on network logs, which cannot provide the granular object-level access auditing mandated by the scenario.

Community Comment Notes

The community overwhelmingly supports this choice, with learners consistently highlighting that CSEK is the deciding factor for regulatory key management. As KLei noted, utilizing CSEK ensures the organization "maintains control over the encryption keys," which directly satisfies the compliance mandate. Additional feedback emphasizes that combining tailored IAM roles with Cloud Audit Logs perfectly aligns with least-privilege principles while avoiding the complexity of third-party solutions.

Official Reference

Exam Strategy

Always map explicit compliance phrases like “control over encryption keys” directly to CSEK or CMEK in GCP, and pair them with Cloud Audit Logs for any access-tracking requirement. Avoid legacy ACLs or third-party tools when native IAM and managed services fully satisfy the prompt.

Frequently Asked Questions

Why not use Google-managed encryption keys here?

Google-managed keys default to automatic encryption where Google holds the keys, violating the explicit requirement for organizational control over encryption keys for compliance.

Why is Cloud Audit Logs preferred over Cloud Monitoring?

Cloud Audit Logs provides immutable, granular records of administrative and data-access events required for compliance auditing, whereas Cloud Monitoring focuses on metrics and alerting.

Related Analysis

← Back to PCSE Study Guide