Courseiva
Trust and security with Google CloudeasyMultiple ChoiceObjective-mapped

Cloud Digital Leader Trust and security with Google Cloud Practice Question

A company's security policy requires that all cloud-to-cloud communication between services must be encrypted in transit. An auditor asks how Google Cloud handles encryption for network traffic between Google services within its network. What is Google's default approach to encryption in transit within its infrastructure?

⚠ Common exam trap

Watch out — candidates often assume internal cloud provider networks are unencrypted for performance reasons, but Google Cloud encrypts all inter-service traffic by default, making options that require customer action or that claim no encryption incorrect.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Google encrypts all traffic between its data centers and internal services by default, with no customer configuration required

Google Cloud encrypts all network traffic between its data centers and internal services by default, using application-layer (e.g., gRPC with TLS) and link-layer encryption (e.g., MACsec or similar). This is a foundational security measure that requires no customer configuration, ensuring data is protected in transit even within Google's own infrastructure.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Google does not encrypt internal traffic by default; customers must configure TLS for all service-to-service communication

    Why it's wrong here

    This option misstates Google's default security posture. Google does not rely on customer-configured TLS for service-to-service traffic; instead, its internal Application Layer Transport Security (ALTS) automatically authenticates and encrypts all inter-service communication, including traffic that never leaves Google's infrastructure. Requiring customers to set up TLS for every service-to-service path would be operationally impossible, which is why Google's default encryption is a foundational security feature rather than a customer obligation.

  • Google encrypts all traffic between its data centers and internal services by default, with no customer configuration required

    Why this is correct

    Google uses Application Layer Transport Security (ALTS) to authenticate and encrypt all traffic between Google services and between data centers by default. This is a core Google infrastructure security commitment, not an optional feature customers must enable.

  • Google only encrypts traffic that crosses the public internet; internal network traffic is unencrypted for performance

    Why it's wrong here

    This option incorrectly assumes Google's internal network is left exposed for performance reasons. In reality, Google uses Application Layer Transport Security (ALTS) to encrypt the vast majority of internal traffic—including traffic between data centers and between services—without meaningful performance degradation, because encryption is implemented at the application layer with hardware acceleration and careful protocol design. While some legacy or low-level infrastructure traffic may have been unencrypted historically, modern Google Cloud default security encrypts internal traffic, and the performance trade-off is considered acceptable, not a reason to forgo encryption.

  • Encryption in transit is the customer's responsibility for all traffic, including traffic within Google's network

    Why it's wrong here

    This option draws the boundary at the wrong place. Customers are indeed responsible for encrypting traffic between their own applications and Google's services (e.g., using TLS for API calls), but traffic that transits Google's internal network—between Google's services, data centers, and regions—is protected by Google's built-in ALTS encryption by default. It is not the customer's responsibility to encrypt traffic within Google's cloud backbone; Google owns and secures that portion of the path. The misconception conflates the customer's endpoint responsibilities with Google's infrastructure protections, which are separate and automatically enforced.

About these practice questions

One of 829 original GCDL practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This GCDL practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCDL exam.