Courseiva
Google Cloud Security →mediumMultiple Select

Cloud Digital Leader Google Cloud Security Practice Question

Which TWO statements about encryption in transit in Google Cloud are correct? (Choose 2)

⚠ Common exam trap

GCDL often tests the misconception that AES-256 is the algorithm for encryption in transit, when AES-256 applies to encryption at rest and TLS is the in-transit mechanism, so candidates who pick the AES option lose the mark.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Google Cloud uses TLS for all external traffic to its APIs.

Option A is correct because Google Cloud terminates all external traffic to its public APIs using TLS (HTTPS), so clients connecting to services such as the Compute Engine API or Cloud Storage API get transport encryption without any extra configuration. Option B is correct because Google encrypts data in transit between its regions and zones by default at the network layer, independent of customer action, so replication and inter-region traffic is protected automatically. Option C is wrong because users do not need to provision TLS certificates for Google-managed services; Google handles the certificates for its endpoints. Option D is wrong because encryption between Google Cloud and the internet is not automatic for all services — for example, a plain HTTP or unencrypted protocol endpoint is not encrypted unless the user configures TLS. Option E is wrong because encryption in transit is not defined as AES-256; TLS negotiates ciphers such as AES-GCM, and AES-256 is more typically associated with encryption at rest, not a blanket statement for transit.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Google Cloud uses TLS for all external traffic to its APIs.

    Why this is correct

    Google Cloud mandates TLS (HTTPS) for every external call to its public API endpoints, covering services like BigQuery and Cloud Storage. This requirement is enforced at the infrastructure level, so clients must use TLS to communicate, regardless of the client library or SDK. As a result, data confidentiality and integrity are protected from the client to Google's edge, and users do not need to configure certificates themselves.

  • ✓

    Data in transit between Google Cloud regions is encrypted by default.

    Why this is correct

    When traffic flows between Google Cloud regions over Google's global backbone, it is encrypted by default using network-level encryption. This includes techniques such as MACsec or IPsec, applied automatically to protect data from physical or logical compromises within the network. Google publicly committed to this since 2017, and it requires no configuration from the customer, covering both inter-region and intra-region traffic. This is an additional layer beyond application-layer TLS.

  • ✗

    Users must configure TLS certificates for all Google Cloud services.

    Why it's wrong here

    The statement that users must configure TLS certificates for all Google Cloud services is incorrect. For Google-managed API endpoints, Google handles the TLS certificates automatically, and customers only need to manage certificates for their own applications running on compute resources. Many services, such as Cloud Load Balancing, even offer managed certificates that auto-renew. Thus, no universal user-side certificate configuration is required for Google Cloud services.

  • ✗

    Data in transit between Google Cloud and the internet is encrypted by default for all services.

    Why it's wrong here

    It is a misconception that all data between Google Cloud and the internet is encrypted by default for every service. For instance, a Compute Engine VM running an HTTP server will accept plaintext HTTP unless the user explicitly enables TLS. Similarly, some legacy services or custom ports may not enforce TLS. While Google encourages TLS and offers managed HTTPS, default encryption applies mainly to Google's API endpoints, not to all traffic initiated or received by user workloads.

  • ✗

    Encryption in transit uses AES-256.

    Why it's wrong here

    Encryption in transit is not characterized by a single cipher like AES-256; it relies on protocols such as TLS 1.2/1.3, which negotiate a cipher suite from existing options. These suites often use ephemeral key exchange algorithms (e.g., ECDHE) for forward secrecy and symmetric encryption like AES-GCM or ChaCha20 for data protection. AES-256, in contrast, is the default symmetric key size for encryption at rest, such as in Persistent Disk or Cloud Storage, so the statement conflates two different encryption contexts.

Quick reference

Symmetric Encryption Algorithm Comparison

AlgorithmKey SizeBlock SizeStatusNotes
AES-128128-bit128-bitCurrent standardNIST approved; WPA3, TLS
AES-256256-bit128-bitCurrent standardPreferred for sensitive / govt data
3DES112-bit effective64-bitDeprecated (2023)Replaced by AES
DES56-bit64-bitBrokenCracked in < 24 h; never deploy
ChaCha20256-bitStream cipherCurrentTLS 1.3, WireGuard

Go deeper

Related to this question

About these practice questions

Courseiva writes every GCDL question from scratch — 848 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Google Cloud exam blueprint

This GCDL practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCDL exam.