Cloud Digital Leader Trust and security with Google Cloud Practice Question
A company's security policy requires that all cloud-to-cloud communication between services must be encrypted in transit. An auditor asks how Google Cloud handles encryption for network traffic between Google services within its network. What is Google's default approach to encryption in transit within its infrastructure?
⚠ Common exam trap
Watch out — candidates often assume internal cloud provider networks are unencrypted for performance reasons, but Google Cloud encrypts all inter-service traffic by default, making options that require customer action or that claim no encryption incorrect.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Google encrypts all traffic between its data centers and internal services by default, with no customer configuration required
Google Cloud encrypts all network traffic between its data centers and internal services by default, using application-layer (e.g., gRPC with TLS) and link-layer encryption (e.g., MACsec or similar). This is a foundational security measure that requires no customer configuration, ensuring data is protected in transit even within Google's own infrastructure.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Google does not encrypt internal traffic by default; customers must configure TLS for all service-to-service communication
Why it's wrong here
This option misstates Google's default security posture. Google does not rely on customer-configured TLS for service-to-service traffic; instead, its internal Application Layer Transport Security (ALTS) automatically authenticates and encrypts all inter-service communication, including traffic that never leaves Google's infrastructure. Requiring customers to set up TLS for every service-to-service path would be operationally impossible, which is why Google's default encryption is a foundational security feature rather than a customer obligation.
- ✓
Google encrypts all traffic between its data centers and internal services by default, with no customer configuration required
Why this is correct
Google uses Application Layer Transport Security (ALTS) to authenticate and encrypt all traffic between Google services and between data centers by default. This is a core Google infrastructure security commitment, not an optional feature customers must enable.
- ✗
Google only encrypts traffic that crosses the public internet; internal network traffic is unencrypted for performance
Why it's wrong here
This option incorrectly assumes Google's internal network is left exposed for performance reasons. In reality, Google uses Application Layer Transport Security (ALTS) to encrypt the vast majority of internal traffic—including traffic between data centers and between services—without meaningful performance degradation, because encryption is implemented at the application layer with hardware acceleration and careful protocol design. While some legacy or low-level infrastructure traffic may have been unencrypted historically, modern Google Cloud default security encrypts internal traffic, and the performance trade-off is considered acceptable, not a reason to forgo encryption.
- ✗
Encryption in transit is the customer's responsibility for all traffic, including traffic within Google's network
Why it's wrong here
This option draws the boundary at the wrong place. Customers are indeed responsible for encrypting traffic between their own applications and Google's services (e.g., using TLS for API calls), but traffic that transits Google's internal network—between Google's services, data centers, and regions—is protected by Google's built-in ALTS encryption by default. It is not the customer's responsibility to encrypt traffic within Google's cloud backbone; Google owns and secures that portion of the path. The misconception conflates the customer's endpoint responsibilities with Google's infrastructure protections, which are separate and automatically enforced.
Go deeper
Related to this question
Learn chapter
Cloud Digital Transformation
Key term
Google Cloud
Google Cloud is a suite of cloud computing services offered by Google that provides infrastructure, platform, and software solutions over the internet.
Key term
Security policy
A security policy is a formal set of rules and guidelines that an organization establishes to protect its information assets and technology resources.
About these practice questions
One of 829 original GCDL practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This GCDL practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCDL exam.