Professional Cloud ArchitectDesign for security and complianceEasy
A defense contractor is migrating sensitive military project data to Google Cloud. They require extremely high network isolation, where data in transit between virtual machines within the same Virtual Private Cloud (VPC) network, even within the same project, must be encrypted. They also need to ensure that this encryption is managed by Google and operates transparently without requiring application-level changes. Which Google Cloud feature provides this level of internal network encryption?
- AInternal IP encryption (Google Cloud's default)
- BCloud VPN
- CVPC Service Controls
- DVPC Firewall Rules
Show answer & explanationAnswer & explanation
Correct answer: A. Internal IP encryption (Google Cloud's default)
Google Cloud encrypts all network traffic between its VMs by default, using TLS or IPsec, even within the same VPC and project. This encryption is managed by Google and is transparent to the application layer, directly meeting the requirement for internal network encryption without application changes.
Why the other options are wrong
- B. Cloud VPN encrypts traffic between Google Cloud and on-premises networks or other cloud providers, not typically for internal VM-to-VM traffic within a VPC.
- C. VPC Service Controls creates security perimeters to prevent data exfiltration but does not provide encryption for internal VM-to-VM traffic within a perimeter.
- D. VPC Firewall Rules control traffic flow but do not encrypt data in transit.
Google Cloud Internal Network Encryption
Google Cloud encrypts all network traffic between Virtual Machines (VMs) and services within its network by default, transparently to users.
- Traffic between VMs is encrypted (TLS or IPsec).
- Encryption is Google-managed and transparent.
- Applies to traffic within VPCs, projects, and regions.
Memory trick: Google's internal network traffic is like a locked box by default. You don't see the lock, but it's there.