Professional Cloud ArchitectDesign for security and complianceEasy
A global bank is migrating its core banking applications to Google Cloud. They have a strict requirement that all data in transit between Google Cloud services (e.g., Compute Engine to Cloud Storage, or BigQuery to Dataflow) must be encrypted by default, without requiring explicit configuration by application developers. This is to ensure a 'secure by default' posture and simplify compliance. How is this requirement met in Google Cloud?
- AVPC Service Controls automatically encrypts traffic within its perimeter.
- BCloud VPN or Cloud Interconnect must be configured for internal traffic.
- CDevelopers must explicitly enable TLS/SSL for all inter-service communication.
- DGoogle Cloud encrypts all internal network traffic between services by default.
Show answer & explanationAnswer & explanation
Correct answer: D. Google Cloud encrypts all internal network traffic between services by default.
Google Cloud automatically encrypts all internal network traffic between its services at the network layer, ensuring a secure-by-default posture without requiring developers to explicitly configure TLS/SSL. This meets the requirement of encryption without explicit developer action. Options B, C, and D are either incorrect, require explicit configuration, or are for external/perimeter security, not default internal encryption.
Why the other options are wrong
- A. VPC Service Controls establishes a security perimeter and controls API access, but it does not inherently provide the default network-layer encryption for all internal traffic between services; Google's network infrastructure handles that.
- B. Cloud VPN and Cloud Interconnect are used for secure connectivity between Google Cloud and on-premises networks, not for encrypting internal traffic between Google Cloud services.
- C. While developers can enable TLS/SSL for application-level encryption, Google Cloud's underlying infrastructure provides default encryption for inter-service communication, making explicit developer configuration unnecessary for the base requirement.
Google Cloud Internal Network Encryption
Google Cloud's default practice of encrypting all network traffic between its services within its infrastructure.
- Traffic is encrypted at the network layer by default.
- No explicit configuration is required by users/developers.
- Ensures a 'secure by default' posture for data in transit.
Memory trick: GCP Network: Built-in Shield, All Traffic Sealed.