tcp-encap is used to specify TCP encapsulation operations for a remote access client to a remote access gateway on an SRX Series Firewall to support IPsec messages encapsulated within a TCP connection from udp port 500 to eg TCP 443
If all remote clients could connect to SRX via udp port 500 then tcp-encap is not needed. But this optional config is not removable from SD Cloud GUI
This issue is fixed as part of Jira - SB-15476