What a key management service does for creating, rotating, and revoking keys
Cloud KMS is Google Cloud's centralized service for creating, managing, and controlling access to cryptographic keys used to encrypt data at rest across Google Cloud services. By default, Google encrypts all data at rest using Google-managed keys, but Cloud KMS lets organizations bring their own key management for compliance, auditing, and control requirements via Customer-Managed Encryption Keys (CMEK). Understanding when and why to use Cloud KMS is key to designing secure, compliant data pipelines on Google Cloud.
Must-know
- Google Cloud encrypts all data at rest by default using Google-managed encryption keys, even if you never touch Cloud KMS.
- Cloud KMS enables Customer-Managed Encryption Keys (CMEK), giving you control over key creation, rotation, and destruction while Google still manages the underlying infrastructure.
- Services like BigQuery, Cloud Storage, and Pub/Sub support CMEK integration, letting you specify a Cloud KMS key to encrypt data instead of relying solely on default Google-managed keys.
- Cloud KMS supports automatic key rotation on a schedule, and rotating a key does not re-encrypt existing data immediately: new data uses the new key version while old data remains decryptable via prior versions.
- Disabling or destroying a Cloud KMS key used for CMEK renders the associated encrypted data permanently inaccessible, so key lifecycle management directly impacts data availability.
- IAM permissions on Cloud KMS keys (e.g., roles/cloudkms.cryptoKeyEncrypterDecrypter) control who can use a key for encryption/decryption, separate from permissions on the data itself, enabling separation of duties.
A data practitioner is setting up a new BigQuery dataset that will store sensitive customer records. The security team requires that the organization retain full control over the encryption key, including the ability to disable or destroy it to immediately revoke access to the data, rather than relying on Google's default key management. What should the data practitioner do?
What you have tried across GCP ADP's objectives, not a readiness score.
Data Preparation and Ingestion
- When to load first and when to transform first, and what sits between the two
- Picking a way to move existing data into Google Cloud
- Judging whether a dataset is trustworthy enough to build on
- Fixing messy records before they reach a report
- Telling CSV, JSON, Parquet, Avro, and relational tables apart, and where each fits
- Picking how to pull data out of a source system
- Matching a workload to the right storage or database service
- Getting files and tables loaded with a CLI, a transfer service, or a client library
Data Analysis and Presentation
- Writing BigQuery SQL that answers a reporting question
- Exploring and charting data inside a hosted notebook
- Turning a question from the business into an analysis that settles it
- Building a dashboard and getting it in front of the right people
- Deciding whether a job calls for Looker or for Looker Studio
- Editing LookML to change what a model exposes
- Spotting a problem worth solving with BigQuery ML or AutoML
- Calling a hosted Google language model straight from BigQuery
- Sequencing a machine learning project from raw data to served predictions
- Building, fitting, and scoring a model with SQL alone
- Running predictions against a model you already trained
- Keeping trained models catalogued in one place
Data Pipeline Orchestration
- Matching a transformation job to Dataproc, Dataflow, Dataform, or a managed alternative
- Weighing whether the transform belongs before or after the load
- Assembling the services a simple transformation pipeline needs
- Putting a query on a schedule and keeping it running
- Watching a Dataflow job and spotting where it stalls
- Reading logs and metrics to work out what a pipeline actually did
- Choosing what should drive a multi-step workflow
- Streaming messages into BigQuery as they arrive rather than in batches
- Wiring a trigger so one event starts the next step
Data Management
- Granting only the access a person or service actually needs
- Controlling who can read a bucket, and what uniform access changes
- Sharing a dataset with another team or company without copying it
- Matching a storage class to how often the data gets read
- Expiring old data automatically so it stops costing money
- Picking somewhere to park data that must be kept but is rarely read
- Comparing the managed backup and restore options across services
- Working out when a second copy is worth what it costs
- Regions, dual-regions, multi-regions, and zones as redundancy choices
- Deciding who should hold the encryption keys
- What a key management service does for creating, rotating, and revoking keys
- Protecting data on the wire versus data sitting on a disk
Coverage checked against the published exam guide on Aug 12, 2026.
These are independent practice questions, written against this certification's published exam guide. They are not the certification vendor's own questions, and not the real exam.