Courseiva
Why Cloud Technology Can Transform BusinesseasyMultiple ChoiceObjective-mapped

Cloud Digital Leader Why Cloud Technology Can Transform Business Practice Question

An organization wants to ensure its data is encrypted at rest and in transit by default on Google Cloud. Which statement is correct?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Data is encrypted at rest and in transit by default.

Google Cloud encrypts data at rest and in transit by default for many services, with customer-managed keys optional.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Customers must use CMEK to encrypt data at rest.

    Why it's wrong here

    CMEK (Customer-Managed Encryption Keys) is an optional feature that lets customers control the key used to protect data at rest; it is not a requirement. By default, Google Cloud automatically encrypts all customer data at rest using Google-managed keys, which are already compliant with many standards. Customers who need to meet specific key-management compliance requirements can choose CMEK, but the default encryption is always on, making this option incorrect.

  • Only data in transit is encrypted by default.

    Why it's wrong here

    This statement is false because Google Cloud encrypts data both at rest and in transit by default. Data is encrypted when stored in Google-managed infrastructure using AES-256 or similar, and data in transit is protected by TLS or other mechanisms. Saying 'only data in transit' ignores the automatic encryption of data at rest, which is a foundational security feature of Google Cloud.

  • Encryption is optional and must be enabled by the customer.

    Why it's wrong here

    Encryption is not optional in Google Cloud; it is enabled by default for virtually all Google Cloud services. Customers cannot disable this default encryption, nor do they need to enable it—it is automatically applied to data as it is written to persistent storage and as it travels over networks. Customers only have the option to add extra layers like CMEK, but that is beyond the already-mandatory default encryption.

  • Data is encrypted at rest and in transit by default.

    Why this is correct

    This is correct because Google Cloud automatically encrypts customer data at rest and in transit by default, with no action required from the customer. Data at rest is encrypted when stored using services like Google Compute Engine, Cloud Storage, and BigQuery, and data in transit is encrypted with TLS or equivalent protocols. This default encryption is a core part of Google's security model, underlying every service, and is also complemented by optional features like CMEK for customers who need key control.

About these practice questions

Courseiva writes every GCDL question from scratch — 829 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This GCDL practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCDL exam.