GCP Professional Data Engineer Practice Question

Your team is designing a Dataflow pipeline that consumes streaming events from Cloud Pub/Sub, processes them in Dataflow, and writes the results to BigQuery. The security team wants to understand how the data will be protected if you make no additional encryption configurations. Which statement correctly describes Google Cloud's default encryption behavior for this end-to-end workflow?

  • Data is encrypted in transit between Pub/Sub and Dataflow workers by default, but at rest in BigQuery you must enable customer-managed encryption keys; otherwise the data is stored unencrypted.

  • All data in Google Cloud is encrypted only if you enable Cloud KMS and provide customer-managed keys; without that, no encryption is applied in transit or at rest.

  • Data in Cloud Storage is encrypted at rest by default, but traffic between Dataflow workers and BigQuery is unencrypted unless you configure VPC Service Controls.

  • Google Cloud automatically encrypts data in transit between its services using TLS and encrypts data at rest with Google-managed keys by default, so no additional configuration is required for this pipeline.

GCP Professional Data Engineer
Ingesting and processing the data
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot