Protecting data on the wire versus data sitting on a disk
Encryption in transit protects data as it moves between systems (e.g., client to Google Cloud, or between services), while encryption at rest protects data stored on disk. Google Cloud applies both by default for its services, but understanding the distinction helps clarify what threats each protects against and where customer-managed keys can be applied.
Must-know
- Encryption in transit uses protocols like TLS to protect data moving over networks, preventing interception or tampering while data travels between clients, services, or data centers.
- Encryption at rest protects data stored on persistent storage (disks, object storage, databases) so that if physical media or storage systems are compromised, the data remains unreadable without the keys.
- Google Cloud encrypts data at rest by default using Google-managed encryption keys, with no action required by the customer for most services like Cloud Storage, BigQuery, and Persistent Disk.
- Customers can choose Customer-Managed Encryption Keys (CMEK) via Cloud KMS or Customer-Supplied Encryption Keys (CSEK) for additional control over data-at-rest encryption, but this applies to storage, not transit.
- Data in transit is automatically encrypted for traffic within Google's network and for connections to Google Cloud APIs/services over HTTPS/TLS; customers should ensure their own client connections also use TLS.
- Encryption in transit and at rest are complementary, not interchangeable: encrypting data at rest does not protect it while being transmitted, and vice versa, so both are needed for comprehensive data protection.
A data engineer uploads a CSV file to a Cloud Storage bucket and leaves it there for downstream batch processing later in the week. Which term describes the protection that automatically safeguards the file's contents while it resides in the bucket?
What you have tried across GCP ADP's objectives, not a readiness score.
Data Preparation and Ingestion
- When to load first and when to transform first, and what sits between the two
- Picking a way to move existing data into Google Cloud
- Judging whether a dataset is trustworthy enough to build on
- Fixing messy records before they reach a report
- Telling CSV, JSON, Parquet, Avro, and relational tables apart, and where each fits
- Picking how to pull data out of a source system
- Matching a workload to the right storage or database service
- Getting files and tables loaded with a CLI, a transfer service, or a client library
Data Analysis and Presentation
- Writing BigQuery SQL that answers a reporting question
- Exploring and charting data inside a hosted notebook
- Turning a question from the business into an analysis that settles it
- Building a dashboard and getting it in front of the right people
- Deciding whether a job calls for Looker or for Looker Studio
- Editing LookML to change what a model exposes
- Spotting a problem worth solving with BigQuery ML or AutoML
- Calling a hosted Google language model straight from BigQuery
- Sequencing a machine learning project from raw data to served predictions
- Building, fitting, and scoring a model with SQL alone
- Running predictions against a model you already trained
- Keeping trained models catalogued in one place
Data Pipeline Orchestration
- Matching a transformation job to Dataproc, Dataflow, Dataform, or a managed alternative
- Weighing whether the transform belongs before or after the load
- Assembling the services a simple transformation pipeline needs
- Putting a query on a schedule and keeping it running
- Watching a Dataflow job and spotting where it stalls
- Reading logs and metrics to work out what a pipeline actually did
- Choosing what should drive a multi-step workflow
- Streaming messages into BigQuery as they arrive rather than in batches
- Wiring a trigger so one event starts the next step
Data Management
- Granting only the access a person or service actually needs
- Controlling who can read a bucket, and what uniform access changes
- Sharing a dataset with another team or company without copying it
- Matching a storage class to how often the data gets read
- Expiring old data automatically so it stops costing money
- Picking somewhere to park data that must be kept but is rarely read
- Comparing the managed backup and restore options across services
- Working out when a second copy is worth what it costs
- Regions, dual-regions, multi-regions, and zones as redundancy choices
- Deciding who should hold the encryption keys
- What a key management service does for creating, rotating, and revoking keys
- Protecting data on the wire versus data sitting on a disk
Coverage checked against the published exam guide on Aug 12, 2026.
These are independent practice questions, written against this certification's published exam guide. They are not the certification vendor's own questions, and not the real exam.