TechNuggets Academy

Ensuring Data Protection

Free Google Cloud Certified - Professional Cloud Security Engineer practice — 6 questions on Ensuring Data Protection, with explanations. No sign-up. Full 12-question mixed test →

Question 1 of 6 · Ensuring Data Protection
A financial services company must retain the ability to instantly and verifiably destroy all encryption key material for regulatory reasons, and the key material must be generated and stored entirely outside of Google's infrastructure at all times, with Google Cloud only calling out to request cryptographic operations. Which approach BEST satisfies this requirement?
Cloud EKM is the only option where the key material never resides in Google Cloud at any point — Google Cloud makes an external call to the partner-hosted key manager for every cryptographic operation, and revoking access at the external system immediately blocks all future operations, satisfying the 'entirely outside Google' and 'instant revocation' requirements.
Question 2 of 6 · Ensuring Data Protection
A company needs to create a test dataset from production credit card numbers for a legacy application whose validation logic depends on the token being the exact same length and character set (digits only) as the original card number. Which Sensitive Data Protection (DLP) transformation should be used?
Format-preserving encryption (FPE), implemented in the DLP API using the FFX mode, encrypts a value while preserving its original format (length and character set), which is exactly what's needed to keep legacy validation logic intact while still protecting the underlying value.
Question 3 of 6 · Ensuring Data Protection
Your organization stores API keys as secrets in Secret Manager. A compliance auditor requires that every call to retrieve a secret's payload (accessSecretVersion) be recorded in Cloud Audit Logs. You confirm that Admin Activity logs are already capturing configuration changes to the secrets, but payload access calls are not appearing anywhere in Cloud Logging. What must you configure to close this gap?
Reading a secret's payload (accessSecretVersion) generates a Data Access audit log of type DATA_READ, and Data Access logs (other than BigQuery) are disabled by default for cost reasons. You must explicitly enable Data Access audit logging with the Data Read log type for the Secret Manager API in IAM & Admin > Audit Logs to capture these calls.
Question 4 of 6 · Ensuring Data Protection
A bank and a credit bureau want to jointly compute a fraud risk score using each other's sensitive raw datasets. Neither organization is willing to expose its raw data to the other, and neither wants even the code author or Google to be able to view the data during processing. Which Google Cloud capability is designed for this use case?
Confidential Space runs a workload inside a hardened, attested Confidential VM environment where neither the infrastructure operator, the data owners, nor the code author can access the data in the clear during processing. It uses workload identity federation and attestation to grant each party's data access only to a verified, trusted binary, making it purpose-built for multi-party confidential collaboration.
Question 5 of 6 · Ensuring Data Protection
You rotate a Cloud KMS CMEK key used to protect a Cloud Storage bucket by creating a new primary key version. What happens to the objects that were already encrypted using the previous key version?
Key rotation in Cloud KMS only changes which key version is used for new encrypt operations going forward; it does not automatically re-encrypt existing ciphertext. Previously written objects remain protected by whichever key version was primary at write time, and that version must stay enabled for those objects to remain decryptable.
Question 6 of 6 · Ensuring Data Protection
A healthcare company must retain patient records in Cloud Storage for 7 years to satisfy regulatory requirements, and the retention guarantee must hold even against project owners or organization administrators attempting to delete or shorten it. Which configuration meets this requirement?
A locked Bucket Lock retention policy makes the retention period immutable and permanently enforced by Cloud Storage itself — it cannot be shortened or removed, even by the project owner or org admin, and objects cannot be deleted or overwritten before the retention period expires, which is exactly the compliance guarantee required.
Ready for the real thing?

The full course has two full-length practice tests, video lessons for every exam domain, hands-on labs and detailed answer explanations.

Start my full course on Udemy →