Intrigued by the art of cloud architecture? Discover how to design, develop, and manage robust, secure, scalable, and dynamic solutions on Google Cloud as you prepare for the Professional Cloud Architect exam!
Prepare and test your skills
Prepare and test your skills
Worked example. The correct answer is already marked and every option is explained below, so there is nothing to select here. To answer questions yourself, start the free trial.
Keep the momentum going with these hand-picked practice scenarios
Want more questions like this?
Get a free certification question every week.
Last updated
A financial services organization is migrating transaction archive data to Google Cloud Storage to satisfy SEC and FINRA regulatory compliance mandates. The compliance team outlines the following mandatory storage requirements:
Which Cloud Storage configuration should you implement to satisfy these requirements?
Place an event-based hold on all bucket objects and configure a Cloud Key Management Service (Cloud KMS) customer-managed encryption key with scheduled key destruction after seven years.
Enable Object Versioning on the bucket, configure an Object Lifecycle Management rule to delete noncurrent versions after seven years, and enforce public access prevention.
Configure a bucket retention policy of seven years, lock the retention policy using Bucket Lock, and configure an Object Lifecycle Management rule to delete objects older than seven years.
Configure Object Retention Lock in Unlocked mode for each object and set a Soft Delete retention duration of seven years on the bucket.
Place an event-based hold on all bucket objects and configure a Cloud Key Management Service (Cloud KMS) customer-managed encryption key with scheduled key destruction after seven years.
Enable Object Versioning on the bucket, configure an Object Lifecycle Management rule to delete noncurrent versions after seven years, and enforce public access prevention.
Configure a bucket retention policy of seven years, lock the retention policy using Bucket Lock, and configure an Object Lifecycle Management rule to delete objects older than seven years.
Bucket Lock is a Cloud Storage compliance feature that allows you to configure a retention policy on a bucket and permanently lock it. When a retention policy is locked, Cloud Storage enforces WORM (Write Once, Read Many) storage behavior across all existing and future objects in the bucket, preventing any object from being modified, overwritten, or deleted until its age exceeds the defined retention period.
403 - retentionPolicyNotMet).Age condition of 7 years will automatically purge objects as soon as their retention expiration date is satisfied.This solution meets every compliance and operational requirement natively within Cloud Storage without custom scripts, external orchestrators, or risk of accidental administrative data deletion.
Configure Object Retention Lock in Unlocked mode for each object and set a Soft Delete retention duration of seven years on the bucket.