Deciding who should hold the encryption keys
Google Cloud encrypts data at rest by default, but customers can choose who controls the encryption keys based on compliance and operational needs. Google-managed keys require no setup, CMEK gives control via Cloud KMS while Google still handles the cryptographic operations, and CSEK lets customers supply and manage their own keys entirely outside Google.
Must-know
- GMEK (Google-managed encryption keys) is the default for services like BigQuery, Cloud Storage, and Compute Engine, with no configuration required and keys fully managed and rotated by Google.
- CMEK (customer-managed encryption keys) lets you create and control key lifecycle (rotation, disabling, destruction) in Cloud KMS while Google still performs encryption/decryption operations, giving an audit trail via Cloud Audit Logs without exposing the raw key.
- CMEK is the right choice when compliance or governance requires demonstrable control over key rotation/revocation and the ability to disable access to data by disabling the key, and is supported by services like BigQuery, Cloud Storage, and Compute Engine.
- CSEK (customer-supplied encryption keys) requires the customer to generate and provide the AES-256 key on each API call; Google uses it transiently for the operation and does not store it, so losing the key means permanent data loss.
- CSEK has narrower support (mainly Compute Engine persistent disks and Cloud Storage) and is chosen only when an organization must retain the raw key material entirely outside Google's infrastructure.
- Destroying a CMEK key in Cloud KMS renders all data encrypted with it permanently unreadable, making key management (not just data deletion) a critical part of data lifecycle and compliance planning.
A healthcare analytics team stores patient records in BigQuery. Company policy requires that the security team be able to immediately revoke access to all data in a dataset by disabling a single key, view key usage in Cloud Audit Logs, and set a key rotation schedule, but the team does not want to manage or transmit raw key material. Which encryption option satisfies these requirements?
What you have tried across GCP ADP's objectives, not a readiness score.
Data Preparation and Ingestion
- When to load first and when to transform first, and what sits between the two
- Picking a way to move existing data into Google Cloud
- Judging whether a dataset is trustworthy enough to build on
- Fixing messy records before they reach a report
- Telling CSV, JSON, Parquet, Avro, and relational tables apart, and where each fits
- Picking how to pull data out of a source system
- Matching a workload to the right storage or database service
- Getting files and tables loaded with a CLI, a transfer service, or a client library
Data Analysis and Presentation
- Writing BigQuery SQL that answers a reporting question
- Exploring and charting data inside a hosted notebook
- Turning a question from the business into an analysis that settles it
- Building a dashboard and getting it in front of the right people
- Deciding whether a job calls for Looker or for Looker Studio
- Editing LookML to change what a model exposes
- Spotting a problem worth solving with BigQuery ML or AutoML
- Calling a hosted Google language model straight from BigQuery
- Sequencing a machine learning project from raw data to served predictions
- Building, fitting, and scoring a model with SQL alone
- Running predictions against a model you already trained
- Keeping trained models catalogued in one place
Data Pipeline Orchestration
- Matching a transformation job to Dataproc, Dataflow, Dataform, or a managed alternative
- Weighing whether the transform belongs before or after the load
- Assembling the services a simple transformation pipeline needs
- Putting a query on a schedule and keeping it running
- Watching a Dataflow job and spotting where it stalls
- Reading logs and metrics to work out what a pipeline actually did
- Choosing what should drive a multi-step workflow
- Streaming messages into BigQuery as they arrive rather than in batches
- Wiring a trigger so one event starts the next step
Data Management
- Granting only the access a person or service actually needs
- Controlling who can read a bucket, and what uniform access changes
- Sharing a dataset with another team or company without copying it
- Matching a storage class to how often the data gets read
- Expiring old data automatically so it stops costing money
- Picking somewhere to park data that must be kept but is rarely read
- Comparing the managed backup and restore options across services
- Working out when a second copy is worth what it costs
- Regions, dual-regions, multi-regions, and zones as redundancy choices
- Deciding who should hold the encryption keys
- What a key management service does for creating, rotating, and revoking keys
- Protecting data on the wire versus data sitting on a disk
Coverage checked against the published exam guide on Aug 12, 2026.
These are independent practice questions, written against this certification's published exam guide. They are not the certification vendor's own questions, and not the real exam.