Cloud Digital Leader Google Cloud Security Practice Question
Which TWO statements about encryption in transit in Google Cloud are correct? (Choose 2)
⚠ Common exam trap
GCDL often tests the misconception that AES-256 is the algorithm for encryption in transit, when AES-256 applies to encryption at rest and TLS is the in-transit mechanism, so candidates who pick the AES option lose the mark.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Google Cloud uses TLS for all external traffic to its APIs.
Option A is correct because Google Cloud terminates all external traffic to its public APIs using TLS (HTTPS), so clients connecting to services such as the Compute Engine API or Cloud Storage API get transport encryption without any extra configuration. Option B is correct because Google encrypts data in transit between its regions and zones by default at the network layer, independent of customer action, so replication and inter-region traffic is protected automatically. Option C is wrong because users do not need to provision TLS certificates for Google-managed services; Google handles the certificates for its endpoints. Option D is wrong because encryption between Google Cloud and the internet is not automatic for all services — for example, a plain HTTP or unencrypted protocol endpoint is not encrypted unless the user configures TLS. Option E is wrong because encryption in transit is not defined as AES-256; TLS negotiates ciphers such as AES-GCM, and AES-256 is more typically associated with encryption at rest, not a blanket statement for transit.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Google Cloud uses TLS for all external traffic to its APIs.
Why this is correct
Google Cloud mandates TLS (HTTPS) for every external call to its public API endpoints, covering services like BigQuery and Cloud Storage. This requirement is enforced at the infrastructure level, so clients must use TLS to communicate, regardless of the client library or SDK. As a result, data confidentiality and integrity are protected from the client to Google's edge, and users do not need to configure certificates themselves.
- ✓
Data in transit between Google Cloud regions is encrypted by default.
Why this is correct
When traffic flows between Google Cloud regions over Google's global backbone, it is encrypted by default using network-level encryption. This includes techniques such as MACsec or IPsec, applied automatically to protect data from physical or logical compromises within the network. Google publicly committed to this since 2017, and it requires no configuration from the customer, covering both inter-region and intra-region traffic. This is an additional layer beyond application-layer TLS.
- ✗
Users must configure TLS certificates for all Google Cloud services.
Why it's wrong here
The statement that users must configure TLS certificates for all Google Cloud services is incorrect. For Google-managed API endpoints, Google handles the TLS certificates automatically, and customers only need to manage certificates for their own applications running on compute resources. Many services, such as Cloud Load Balancing, even offer managed certificates that auto-renew. Thus, no universal user-side certificate configuration is required for Google Cloud services.
- ✗
Data in transit between Google Cloud and the internet is encrypted by default for all services.
Why it's wrong here
It is a misconception that all data between Google Cloud and the internet is encrypted by default for every service. For instance, a Compute Engine VM running an HTTP server will accept plaintext HTTP unless the user explicitly enables TLS. Similarly, some legacy services or custom ports may not enforce TLS. While Google encourages TLS and offers managed HTTPS, default encryption applies mainly to Google's API endpoints, not to all traffic initiated or received by user workloads.
- ✗
Encryption in transit uses AES-256.
Why it's wrong here
Encryption in transit is not characterized by a single cipher like AES-256; it relies on protocols such as TLS 1.2/1.3, which negotiate a cipher suite from existing options. These suites often use ephemeral key exchange algorithms (e.g., ECDHE) for forward secrecy and symmetric encryption like AES-GCM or ChaCha20 for data protection. AES-256, in contrast, is the default symmetric key size for encryption at rest, such as in Persistent Disk or Cloud Storage, so the statement conflates two different encryption contexts.
Quick reference
Symmetric Encryption Algorithm Comparison
| Algorithm | Key Size | Block Size | Status | Notes |
|---|---|---|---|---|
| AES-128 | 128-bit | 128-bit | Current standard | NIST approved; WPA3, TLS |
| AES-256 | 256-bit | 128-bit | Current standard | Preferred for sensitive / govt data |
| 3DES | 112-bit effective | 64-bit | Deprecated (2023) | Replaced by AES |
| DES | 56-bit | 64-bit | Broken | Cracked in < 24 h; never deploy |
| ChaCha20 | 256-bit | Stream cipher | Current | TLS 1.3, WireGuard |
Go deeper
Related to this question
Learn chapter
Google Maps Platform for Location Services
Key term
Transport Layer Security
Transport Layer Security (TLS) is a cryptographic protocol that provides secure, encrypted communication between two devices over a network, such as between a web browser and a server.
Key term
Hypertext Transfer Protocol Secure
Hypertext Transfer Protocol Secure, or HTTPS, is the secure version of HTTP that encrypts data between a web browser and a website using SSL/TLS to protect sensitive information like passwords and credit card numbers.
About these practice questions
Courseiva writes every GCDL question from scratch — 848 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Google Cloud exam blueprint
This GCDL practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCDL exam.