Unlock the power of your data in the cloud! Get hands-on with Google Cloud's core data services like BigQuery and Looker to validate your practical skills in data ingestion, analysis, and management, and earn your Associate Data Practitioner certification!
Prepare and test your skills
Prepare and test your skills
Worked example. The correct answer is already marked and every option is explained below, so there is nothing to select here. To answer questions yourself, start the free trial.
Keep the momentum going with these hand-picked practice scenarios
Want more questions like this?
Get a free certification question every week.
Last updated
An organization is deploying a data analytics pipeline on Google Cloud and needs to define security controls for different stages of the data lifecycle. The security architecture requires two fundamental protections:
Which combination of mechanisms correctly distinguishes between encryption in transit and encryption at rest to satisfy these requirements?
Apply Secure Shell (SSH) port forwarding exclusively for encryption at rest, and apply database table partitioning for encryption in transit.
Apply server-side disk-level encryption for encryption in transit, and apply Transport Layer Security (TLS/SSL) for encryption at rest.
Apply Transport Layer Security (TLS/SSL) for encryption in transit, and apply server-side disk-level encryption for encryption at rest.
Apply Customer-Managed Encryption Keys (CMEK) over TLS for encryption in transit, and apply unencrypted temporary local storage for encryption at rest.
Apply Secure Shell (SSH) port forwarding exclusively for encryption at rest, and apply database table partitioning for encryption in transit.
Apply server-side disk-level encryption for encryption in transit, and apply Transport Layer Security (TLS/SSL) for encryption at rest.
Apply Transport Layer Security (TLS/SSL) for encryption in transit, and apply server-side disk-level encryption for encryption at rest.
Transport Layer Security (TLS) and server-side disk-level encryption represent two complementary layers of data protection in Google Cloud. Encryption in transit protects network packets while they are being transmitted between a client and Google Cloud (or between Google Cloud services) by establishing an encrypted communication channel. Encryption at rest protects stored data by transforming readable plaintext into ciphertext before it is committed to non-volatile physical storage devices such as persistent disks, solid-state drives (SSDs), or object storage buckets.
This configuration aligns precisely with Google Cloud security best practices by mapping each protection state (data in transit vs. data at rest) to its dedicated cryptographic protocol and storage mechanism, ensuring complete end-to-end security.
Apply Customer-Managed Encryption Keys (CMEK) over TLS for encryption in transit, and apply unencrypted temporary local storage for encryption at rest.