Professional Cloud Security Engineer
Prepare and test your skills
Prepare and test your skills
Worked example. The correct answer is already marked and every option is explained below, so there is nothing to select here. To answer questions yourself, start the free trial.
Keep the momentum going with these hand-picked practice scenarios
Want more questions like this?
Get a free certification question every week.
Last updated
A financial enterprise uses Google Cloud Storage to store sensitive audit logs and transaction records. The bucket is configured with Customer-Managed Encryption Keys (CMEK) managed in Cloud Key Management Service (Cloud KMS).
To align with internal data governance and cost optimization frameworks, the security team implements the following configurations:
SetStorageClass action to transition objects from Standard to Archive storage after 90 days.Delete action for objects older than 7 years.How do these lifecycle actions and security controls affect object availability, legal holds, and encryption states?
Objects with an active legal hold still transition to Archive storage but cannot be deleted by lifecycle rules, and existing objects continue to be encrypted with their original CMEK key version rather than automatically re-encrypting when keys rotate.
Lifecycle deletion actions permanently delete objects older than 7 years regardless of legal holds, and transitioning objects to Archive storage automatically falls back to Google default encryption.
Transitioning objects to Archive storage decrypts and re-encrypts the payload with the latest primary CMEK version, and disabling older key versions in Cloud KMS has no impact on existing archived data availability.
Objects under an active legal hold are completely excluded from all lifecycle actions including storage class transitions, and rotating the Cloud KMS key triggers an automatic rewrite that re-encrypts all objects with the new primary key version.
Objects with an active legal hold still transition to Archive storage but cannot be deleted by lifecycle rules, and existing objects continue to be encrypted with their original CMEK key version rather than automatically re-encrypting when keys rotate.
In Google Cloud Storage, Object Lifecycle Management allows organizations to automate data tiering and deletion. However, governance controls like Legal Holds and cryptographic policies governing Customer-Managed Encryption Keys (CMEK) dictate exact availability and protection states during these automated operations.
Delete actions. However, non-destructive lifecycle actions—specifically SetStorageClass transitions (such as moving from Standard to Nearline, Coldline, or Archive)—are permitted and execute as scheduled. This ensures cost optimization without compromising data preservation.This architecture balances compliance mandates (preserving evidentiary records via legal holds), financial governance (downward storage class tiering to Archive), and cryptographic integrity (maintaining established envelope encryption keys).
Lifecycle deletion actions permanently delete objects older than 7 years regardless of legal holds, and transitioning objects to Archive storage automatically falls back to Google default encryption.
Transitioning objects to Archive storage decrypts and re-encrypts the payload with the latest primary CMEK version, and disabling older key versions in Cloud KMS has no impact on existing archived data availability.
Objects under an active legal hold are completely excluded from all lifecycle actions including storage class transitions, and rotating the Cloud KMS key triggers an automatic rewrite that re-encrypts all objects with the new primary key version.