Objective 5.2

CDL

Describe the business value of making Google part of an organization’s security team with its defense-in-depth, multilayered approach to cloud security.

Objective 5.2 sits in Trust and Security with Google Cloud, which carries 18% of the Cloud Digital Leader exam. The questions below are original, written from the official objective title above, and each explanation cites the Google Cloud page it rests on.

Objective title verbatim from the official objectives. Google Cloud exam page

A worked example

Shown solved, with the whole explanation open: this is what every question here carries.

5-2Trust and Security with Google Cloud

A company asks what it has to configure before its stored data is encrypted on Google Cloud. What does Google do by default?

Encryption starts once a KMS key is createdKMS adds control on top of coverage already present.
Encryption applies only to Cloud Storage bucketsCoverage is not limited to one storage product.
All customer content is encrypted with no actionCorrect · your answerCorrect. Key ownership is the remaining choice.
Encryption must be enabled per project by policyNo per-project switch turns the baseline on.

Correct.

Concept

A protection that is on by default removes a whole class of configuration error. What remains negotiable is who holds the keys, not whether the bytes are covered.

Why C

Google encrypts all customer content stored at rest, without any action from the customer, using one or more encryption mechanisms.

Source

Google encrypts all customer content stored at rest, without any action from you, using one or more encryption mechanisms. The following sections describe the mechanisms that we use to encrypt customer content.

Google Cloud: Default encryption at rest, checked August 2026
#gcp#encryption#default-encryption#data-protection

Now you: objective 5.2 questions

No account needed. The explanation opens when you answer.

Sample question 1 of 3

5-2Trust and Security with Google Cloud

A security team asks which algorithm protects data at the storage level on Google Cloud. What is used by default?

Sample question 2 of 3

5-2Trust and Security with Google Cloud

A security team asks how the damage from one compromised key is contained. How does Google partition data at rest?

Sample question 3 of 3

5-2Trust and Security with Google Cloud

An organization needs its data logically separated from other tenants by encryption. What must it enable to get that?

Full Cloud Digital Leader question bank coming

We’re writing the complete bank from the official objectives right now. Leave your email and we’ll tell you when it ships, nothing else, ever.

Read the sources

These are the official pages the questions above cite. Reading them is studying the objective from the primary source, which is what the explanations point you toward anyway.

More objectives in Trust and Security with Google Cloud