Professional Cloud Security Engineer flashcards
137 free flashcards. Tap a card to flip it.
Cloud External Key Manager (EKM)
Flip cardCloud EKM enables you to encrypt data in Google Cloud using encryption keys that you manage in a supported external key management system, outside of Google's infrastructure.
- Keys remain outside Google Cloud.
- Provides complete control over key lifecycle.
- Suitable for stringent regulatory compliance.
Memory trick: External Keys Mean Ultimate Control Outside.
Cloud SQL CMEK with Cloud HSM
Flip cardUsing Customer-managed encryption keys (CMEK) for Cloud SQL, where the keys themselves are protected by Google Cloud's FIPS 140-2 Level 3 validated Hardware Security Module (HSM) via Cloud KMS.
- Provides enhanced control over encryption keys.
- Meets strict compliance requirements like FIPS 140-2 Level 3.
- Keys are stored and operations performed within an HSM.
Memory trick: SQL's data is safe, with CMEK and HSM's FIPS-grade embrace.
BigQuery Column-level Security with Data Masking
Flip cardA BigQuery feature that allows you to define policies to mask (transform) data in specific columns based on user permissions, ensuring sensitive information is never exposed in plain text while still enabling analytical operations.
- Applies to columns, not rows.
- Masks data based on user roles/permissions.
- Allows aggregate queries on masked data.
Memory trick: To see or not to see, BigQuery's mask is the key!
Cloud Storage Retention Policy with Object Lock
Flip cardA Cloud Storage feature that enforces immutability on objects within a bucket for a specified duration, preventing deletion or modification by any user, including administrators, to meet regulatory or compliance requirements.
- Applies to all objects in a bucket (or specific objects if configured).
- Prevents deletion and modification for the retention period.
- Works even for users with 'Owner' permissions.
- Essential for WORM (Write Once, Read Many) compliance.
Memory trick: To Lock your data for good, a Retention Policy and Object Lock are understood!
DLP CryptoReplaceFfxFpe
Flip cardA Google Cloud DLP de-identification method that uses format-preserving encryption (FFX mode) to replace sensitive data with an encrypted value that retains the original data's format and character set.
- Preserves data format (e.g., length, character type).
- Irreversible without the encryption key.
- Useful for maintaining data utility in analytics while de-identifying.
Memory trick: FPE masks data but keeps its shape, like a secret code.
VPC Service Controls
Flip cardA Google Cloud security feature that allows you to create a security perimeter around sensitive Google Cloud resources to mitigate data exfiltration risks.
- Restricts operations on supported services to authorized networks.
- Prevents data movement to unauthorized locations.
- Enhances compliance for highly sensitive workloads.
Memory trick: Build a fence around your data, keeping it safe inside.
Cloud KMS Hardware-backed Keys (Cloud HSM)
Flip cardA Cloud KMS key type that uses FIPS 140-2 Level 3 validated Hardware Security Modules (HSMs) to generate, store, and perform cryptographic operations, offering enhanced security, high availability, and durability for encryption keys within Google Cloud.
- Keys generated and stored in FIPS 140-2 Level 3 HSMs.
- Offers strongest security guarantees for keys within GCP.
- Integrated with Cloud KMS for central management and auditing.
- Provides high availability and durability for keys.
Memory trick: For keys, choose your vault: Software, Hardware, or External's default!
Cloud Storage Default CMEK
Flip cardA Cloud Storage bucket setting that automatically encrypts all new objects uploaded to the bucket with a specified Customer-Managed Encryption Key (CMEK), preventing uploads of objects encrypted with other methods.
- Applies to new objects uploaded to the bucket.
- Enforces a specific Cloud KMS key for encryption.
- Prevents bypassing CMEK by disallowing other encryption types.
Memory trick: For storage security, set the default key, or risk a breach, you see!
Cloud KMS Key Protection Levels
Flip cardCloud KMS offers different protection levels for cryptographic keys, determining how and where the key material is stored and cryptographic operations are performed.
- SOFTWARE: Keys stored in software.
- HSM: Keys stored in hardware security modules (FIPS 140-2 Level 3).
- EXTERNAL: Keys managed by an external key manager (Cloud EKM).
Memory trick: Software for speed, HSM for strength, External for sovereignty.
Assured Workloads
Flip cardA Google Cloud offering that helps customers meet compliance and regulatory requirements by establishing a secure and compliant environment for sensitive workloads.
- Enforces data residency and sovereign controls.
- Limits Google personnel access based on geography.
- Supports various compliance regimes (FedRAMP, IL4/IL5, C5, etc.).
Memory trick: Assured Workloads: Your compliance shield, keeping data secure on a regulated field.
Secret Manager Automatic Rotation
Flip cardA Google Cloud Secret Manager feature that automates the process of updating secrets at a specified interval, typically using a Cloud Function to generate and apply new secret values.
- Enhances security by regularly changing credentials.
- Reduces operational overhead for secret management.
- Supports custom logic for secret generation and update.
Memory trick: Rotate your secrets automatically, like clockwork.
Google Cloud Assured Workloads
Flip cardA Google Cloud service that helps customers meet specific compliance and regulatory requirements by providing predefined, compliance-focused environments that enforce data residency, personnel access controls, and operational transparency.
- Provides compliance-specific environments (e.g., FedRAMP, C5).
- Enforces data residency and personnel access controls.
- Offers operational transparency and support tailored to compliance.
- Simplifies meeting stringent regulatory requirements.
Memory trick: For compliance, Google's 'Assured Workloads' ensures your data's journey is truly secure and sound!
Cloud KMS Default Key
Flip cardA Cloud KMS feature that allows you to specify a default Customer-Managed Encryption Key (CMEK) at the project or folder level, which is then automatically applied to new resources in supported Google Cloud services.
- Simplifies CMEK adoption across an organization.
- Ensures consistent encryption policy enforcement.
- Reduces manual configuration for new resources.
Memory trick: Set a default key, and new resources will just pick it up.
Cloud Asset Inventory & Security Health Analytics for Compliance
Flip cardCloud Asset Inventory provides a comprehensive inventory of all Google Cloud assets and their metadata, while Security Health Analytics (within Security Command Center) analyzes this inventory to detect misconfigurations and compliance violations against security standards.
- Cloud Asset Inventory catalogs all resources and their configurations.
- Security Health Analytics detects common misconfigurations (e.g., disabled UBLA).
- Used for security posture management and compliance auditing.
- Integrates to provide actionable insights for security teams.
Memory trick: To check your cloud's health, Inventory your assets, then Analyze for wealth!
Cloud Audit Logs with WORM Storage
Flip cardGoogle Cloud's built-in auditing service combined with immutable storage to create tamper-proof records of activity for compliance.
- Records admin and data access events.
- WORM (Write Once, Read Many) ensures immutability.
- Critical for regulatory compliance and forensic analysis.
Memory trick: Audit logs go to WORM, forever sealed and never reformed.
Cloud SQL Private IP with Hybrid Connectivity and SSL/TLS
Flip cardConfiguring Cloud SQL with a private IP address, establishing secure private network connectivity from on-premises via Cloud VPN or Cloud Interconnect, and enforcing SSL/TLS for encrypted and authenticated database connections.
- Private IP removes public internet exposure.
- Cloud VPN/Interconnect provides secure hybrid connectivity.
- SSL/TLS encrypts and authenticates client-server traffic.
- Ensures end-to-end secure communication for sensitive data.
Memory trick: To keep your SQL safe, private IP and VPN/Interconnect are the key, with SSL/TLS for data security!
VPC Service Controls & Uniform Bucket-Level Access for Cloud Storage
Flip cardA combination of security controls to prevent data exfiltration from Cloud Storage buckets and enforce consistent access policies.
- Uniform bucket-level access simplifies and centralizes permissions.
- VPC Service Controls creates a security perimeter around services.
- Together, they prevent public access and data exfiltration.
Memory trick: Uniform access for the bucket, VPC Service Controls builds the gate, no data escapes, it's too late!
Cloud SQL Private IP with SSL/TLS
Flip cardConfiguring Cloud SQL instances to use an internal Private IP address and enforcing SSL/TLS for all connections, ensuring secure and private network access.
- Database is not exposed to the public internet.
- Connections are encrypted (SSL/TLS).
- Access is restricted to authorized VPC networks.
Memory trick: Private IP is the secret door, SSL is the lock, keeping data safe from any shock.
Data Loss Prevention (DLP) API
Flip cardA Google Cloud service that helps discover, classify, and protect sensitive data (infoTypes) across various data sources and content types, including text, images, and structured data.
- Identifies over 150 built-in infoTypes (e.g., credit card numbers, SSN).
- Supports de-identification methods like redaction, tokenization, FPE.
- Can scan data at rest and in transit.
Memory trick: DLP finds hidden secrets, like a digital detective.
Secret Manager Access with IAM Conditions
Flip cardUsing IAM roles combined with IAM Conditions to grant granular access to Secret Manager resources, such as restricting access to only the latest version of a secret or specific actions.
- Role 'Secret Manager Secret Accessor' grants payload access.
- IAM Conditions filter access based on resource attributes or request properties.
- 'resource.name' can filter by secret or version path.
- 'secretmanager.secretVersion.access' is the method for payload retrieval.
Memory trick: To unlock a secret, combine the right role with a strict condition, or risk over-permission!
Cloud Audit Logs with Bucket Lock
Flip cardExporting Cloud Audit Logs to a Cloud Storage bucket that has a Bucket Lock policy applied, ensuring the logs are immutable and cannot be deleted or modified for a specified retention period.
- Provides WORM compliance for audit trails.
- Essential for regulatory and legal requirements.
- Protects against tampering, even by privileged users.
Memory trick: Lock your logs in storage to keep them forever true.
Cloud Storage Retention Policy & Object Roles
Flip cardConfiguring Cloud Storage with specific IAM roles for granular object access and a bucket retention policy to prevent accidental data deletion and enforce immutability.
- IAM roles (e.g., `objectViewer`, `objectCreator`) ensure least privilege.
- Bucket retention policy locks objects for a specified duration.
- Helps prevent accidental data loss and ensures compliance.
Memory trick: Roles for access, retention for keeping data from being lost forever.
Cloud Key Management Service (KMS)
Flip cardA cloud-hosted key management service that lets you manage cryptographic keys for your cloud services in the same way you manage keys on-premises.
- Manages symmetric and asymmetric encryption keys.
- Integrates with many Google Cloud services for CMEK.
- Provides auditing and access control for keys.
Memory trick: KMS: Keeping My Secrets safe in the Cloud.
Cloud Storage Bucket Lock
Flip cardA feature that allows you to configure a retention policy on a Cloud Storage bucket, preventing objects from being deleted or modified for a specified duration.
- Enforces immutability on objects.
- Protects against accidental or malicious deletion/modification.
- Adheres to WORM (Write Once, Read Many) principles.
Memory trick: Lock your buckets to keep data forever, like a digital vault.
_Required Log Buckets with Lock
Flip cardA Google Cloud Logging feature that automatically routes all Admin Activity and Data Access logs to a dedicated, unmodifiable log bucket, ensuring immutable storage for compliance.
- Automatically collects Admin Activity and Data Access logs.
- Configurable at the organization level.
- Retention policies can be applied and locked, preventing deletion even by organization administrators.
- Essential for strict regulatory compliance requirements.
Memory trick: Required logs locked tight, no one can delete, day or night.
Security Health Analytics (SHA)
Flip cardSecurity Health Analytics is a Security Command Center service that continuously scans your Google Cloud assets for security misconfigurations, vulnerabilities, and compliance violations. It provides findings related to IAM, networking, storage, and other services.
- Continuously assesses cloud resource configurations.
- Identifies misconfigurations and compliance issues.
- Integrated with Security Command Center.
Memory trick: Health Analytics checks config for compliance.
Cloud Logging Log Sink to Pub/Sub
Flip cardA Cloud Logging feature that forwards selected log entries in real-time to a Pub/Sub topic, enabling immediate consumption by external systems like SIEMs for real-time analysis and incident response.
- Provides low-latency, real-time log streaming.
- Ensures reliable message delivery.
- Ideal for integrating with external SIEMs, SOARs, or custom analytics platforms.
- Supports filtering to send only relevant logs.
Memory trick: Pub/Sub is the 'Post Office' for your logs, ensuring 'swift' and 'reliable' delivery to your SIEM.
Chronicle Security Operations
Flip cardA cloud-native security analytics platform that ingests, normalizes, and analyzes vast amounts of security telemetry from an enterprise's entire technology stack to enable advanced threat detection, investigation, and response.
- Handles petabytes of security data.
- Provides advanced threat hunting and correlation capabilities.
- Integrates data from Google Cloud, on-premises, and third-party sources.
- Designed for rapid incident investigation and response.
Memory trick: Chronicle 'chronicles' all your security data to find hidden threats.
Security Command Center (SCC)
Flip cardSecurity Command Center is Google Cloud's native security and risk management platform. It helps detect, investigate, and act on threats across your Google Cloud environment, providing a centralized view of security posture, assets, and findings.
- Centralized security posture management.
- Aggregates findings from multiple sources.
- Supports vulnerability management, threat detection, and compliance.
Memory trick: SCC is the brain of Cloud security.
SCC Findings to Cloud Monitoring Alerts
Flip cardSecurity Command Center findings, including those from Security Health Analytics, can be exported to Cloud Monitoring as metrics, allowing for the creation of alert policies for real-time notifications.
- SCC findings automatically appear in Cloud Monitoring.
- Built-in SHA detectors cover common misconfigurations.
- Cloud Monitoring alert policies can be based on SCC finding metrics.
- Enables timely notification for critical security posture issues.
Memory trick: SCC finds the issue, Monitoring makes the alert ring loud and clear.
Policy Intelligence for Firewall Analysis
Flip cardA suite of Google Cloud tools (including Firewall Insights, Policy Troubleshooter, and Policy Analyzer) that helps understand, analyze, and optimize IAM policies and firewall rules, identifying misconfigurations and providing recommendations.
- Analyzes firewall rules for shadowed, unused, or overly permissive rules.
- Helps understand the impact of firewall rules on network traffic.
- Provides recommendations for policy optimization.
- Assists in identifying and troubleshooting policy violations.
Memory trick: Policy Intelligence is your 'firewall policy guru', giving 'insights' and 'troubleshooting' advice.
Policy Analyzer
Flip cardA Google Cloud Policy Intelligence tool that helps security teams understand, audit, and verify existing IAM policies by analyzing who has access to what resources and under what conditions.
- Audits existing IAM policies.
- Identifies access paths and effective permissions.
- Helps verify least privilege and compliance.
- Can query policies across projects and organizations.
Memory trick: Policy Analyzer analyzes all policies, to see who's got what access.
Event Threat Detection (ETD)
Flip cardA Security Command Center service that automatically monitors Google Cloud logs for specific, pre-defined threats like cryptocurrency mining, malware, and suspicious network activity.
- Analyzes logs from various Google Cloud services.
- Detects threats like crypto mining, ransomware, data exfiltration.
- Generates findings in Security Command Center.
- Part of Security Command Center Premium tier.
Memory trick: ETD detects bad events from logs, like a security guard on watch.
Container Threat Detection (CTD)
Flip cardA Google Cloud service that provides runtime threat detection for Google Kubernetes Engine (GKE) clusters, identifying suspicious activities like reverse shells, cryptomining, and binary tampering, and reporting findings to Security Command Center.
- Monitors GKE clusters for runtime threats.
- Detects suspicious container behavior (e.g., process execution, file access).
- Generates findings in Security Command Center.
- A fully managed service for container security.
Memory trick: CTD is your 'Container Threat Detector', watching your 'ships' for 'pirates' at sea.
Aggregated Log Sinks with Locked Log Buckets
Flip cardA Google Cloud Logging strategy to centralize all Cloud Audit Logs from an entire organization to a single, immutable log bucket with a long-term retention policy to meet compliance and security analysis needs.
- Aggregated sinks collect logs from all projects/folders in an organization.
- Dedicated log buckets provide centralized, isolated storage.
- Locked retention policies ensure immutability and prevent deletion.
- Covers Admin Activity, Data Access, and System Event logs.
Memory trick: Aggregated sinks gather all logs, and a locked bucket keeps them forever safe.
Cloud Logging _Required Log Buckets with Locks
Flip cardSpecial log buckets in Google Cloud Logging that cannot be disabled or excluded from routing, combined with a bucket lock to make their retention policy immutable, ensuring long-term, tamper-proof log storage for compliance.
- Ensures logs are always captured (required).
- Custom retention periods can be set.
- Bucket locks prevent retention policy changes or bucket deletion.
- Critical for regulatory compliance (e.g., GDPR, HIPAA, PCI DSS).
Memory trick: Required Buckets with Locks are like a 'digital vault' for your logs, making them 'required', 'retained', and 'immutable'.
Logs Explorer for API Call Investigation
Flip cardCloud Logging's Logs Explorer enables detailed filtering and analysis of Admin Activity and Data Access logs to trace all API calls, including failed ones, by specific principals across an organization.
- Uses Cloud Logging Logs Explorer
- Requires both Admin Activity and Data Access logs
- Allows filtering by `principalEmail` and time ranges
Memory trick: Explore all logs for that service account, even the failed calls!
Admin Activity Logs with Locked _Required Log Buckets
Flip cardAdmin Activity logs record API calls that modify resource configurations. When routed to a _Required Log Bucket with a bucket lock, these logs become immutable and cannot be disabled, altered, or deleted, ensuring compliance for administrative actions.
- Admin Activity logs are enabled by default for auditing administrative actions.
- _Required Log Buckets ensure logs are always collected.
- Bucket locks make retention policies immutable, preventing deletion/modification.
- Crucial for compliance and forensic analysis of administrative changes.
Memory trick: Admin Activity in a 'Locked Required Bucket' means your audit trail is 'safe and sound' for 'ages'.
Monitoring Query Language (MQL)
Flip cardA powerful, declarative query language used in Google Cloud Monitoring for defining, aggregating, and transforming metrics and log data to create custom dashboards, alerting policies, and troubleshoot issues.
- Used for both metrics and log-based metrics.
- Supports complex aggregations, transformations, and filtering.
- Enables creation of advanced alerting policies and dashboards.
- Offers flexible control over data visualization.
Memory trick: MQL is the 'Master Query Language' for your Monitoring 'metrics' and 'logs'.
Organization Policy Service (Custom Constraints)
Flip cardThe Organization Policy Service allows administrators to centrally control resource configurations across a Google Cloud organization. Custom constraints extend this capability, enabling enforcement of specific, user-defined policies, such as requiring CMEK for Cloud Storage buckets.
- Centralized control over resource configurations.
- Enforces policies at the organization/folder/project level.
- Custom constraints allow fine-grained, preventive policy enforcement.
Memory trick: Org Policy enforces the rules from the top.
Artifact Analysis
Flip cardA Google Cloud service that provides vulnerability scanning, metadata management, and policy enforcement for software artifacts, particularly container images, stored in Container Registry or Artifact Registry.
- Scans container images for known vulnerabilities.
- Integrates with CI/CD pipelines.
- Supports various vulnerability databases (e.g., OSV, CVE).
- Helps enforce security policies for artifacts.
Memory trick: Artifact Analysis inspects your container 'artifacts' for any hidden 'vulnerabilities'.
Cloud Audit Logs: Data Access logs
Flip cardData Access logs record API calls that read the configuration or metadata of resources, as well as user-provided data. These logs are not enabled by default for all resource types due to their volume and are typically used for auditing data access.
- Records reading/writing of user-provided data.
- Crucial for data exfiltration investigations.
- Often disabled by default to manage log volume.
Memory trick: Admin changes, Data reads, System events.
Web Security Scanner
Flip cardA Google Cloud service that scans deployed web applications for common web vulnerabilities such as XSS, SQL injection, and insecure headers, and reports findings to Security Command Center.
- Actively crawls and analyzes web applications.
- Detects common web vulnerabilities (XSS, SQLi, etc.).
- Reports findings to Security Command Center.
- Can be scheduled for continuous scanning.
Memory trick: Web Security Scanner is like a 'web spider' looking for 'security holes' in your application.
Cloud Monitoring MQL for Audit Logs
Flip cardCloud Monitoring Query Language (MQL) can be used to query and filter Cloud Audit Logs ingested into Cloud Logging, enabling the creation of custom alerts for specific security-related events or misconfigurations.
- MQL allows complex filtering and aggregation of log entries.
- Audit logs contain `protoPayload` with detailed request/response information.
- Alerts can be triggered based on specific field values within log entries.
Memory trick: MQL filters audit logs to catch bucket access changes, ensuring uniform security.
Admin Activity Logs with Retention Lock
Flip cardAdmin Activity logs record API calls or administrative actions. When routed to a _Required Log Bucket with a retention lock, these logs are immutably stored for a specified duration, meeting stringent compliance needs.
- Admin Activity logs track administrative actions.
- _Required Log Buckets ensure mandatory log destinations.
- Retention locks prevent premature deletion for compliance.
Memory trick: Admin's actions are locked for seven years, no deleting!
Container Security Duo: Artifact Analysis & CTD
Flip cardArtifact Analysis scans container images for vulnerabilities (pre-deployment), while Container Threat Detection (CTD) monitors running GKE containers for runtime threats and suspicious activity (post-deployment).
- Artifact Analysis: Image vulnerability scanning.
- Container Threat Detection: Runtime container threat monitoring.
- Together provide end-to-end container security.
- Integrated with Security Command Center.
Memory trick: Analyze before you deploy, detect threats as they play.
Security Health Analytics (SHA) Custom Modules
Flip cardA feature of Security Health Analytics that allows users to define custom security checks and compliance standards for their Google Cloud resources, extending SHA's built-in detectors.
- Define custom security compliance rules.
- Checks for resource misconfigurations.
- Integrates with Security Command Center and Cloud Monitoring.
- Enables monitoring against organization-specific standards.
Memory trick: SHA custom modules tailor the health checks to your rules.
Event Threat Detection (ETD) for Anomalies
Flip cardA Security Command Center service that automatically detects suspicious and anomalous activities, like unusual API calls or access from unexpected locations, leveraging Google's threat intelligence and machine learning.
- Detects anomalous behavior in logs.
- Identifies insider threats and compromised accounts.
- Uses Google's threat intelligence and ML.
- Generates high-fidelity findings in Security Command Center.
Memory trick: ETD spots the unexpected API calls, like a security camera watching for strange movements.
Data Access Logs
Flip cardCloud Audit Logs that record API calls that read or modify user-provided data within Google Cloud services, such as Cloud Storage or BigQuery.
- Records data read/write operations.
- Must be explicitly enabled for most services (e.g., Cloud Storage).
- Crucial for data exfiltration investigations.
- Can incur costs due to high volume.
Memory trick: Data Access logs show who tried to access your data's treasure chest.
Policy Intelligence & Audit Logs for Firewall Analysis
Flip cardCloud Audit Logs (Admin Activity) record who made changes to firewall rules. Policy Intelligence's Policy Analyzer helps understand the impact of firewall rules by analyzing reachability and effective policies, crucial for security investigations.
- Admin Activity logs track firewall rule modifications.
- Policy Analyzer evaluates rule impact and reachability.
- Together, they provide comprehensive firewall change and impact analysis.
Memory trick: Audit logs show 'who', Policy Analyzer shows 'what' they enable.
Cloud Logging _Required Log Bucket
Flip cardThe `_Required` log bucket is a special Cloud Logging bucket that automatically receives all Admin Activity logs and System Event logs for a project, folder, or organization. It cannot be disabled, its retention can only be increased (default 400 days), and it ensures log immutability for compliance.
- Automatically receives Admin Activity and System Event logs.
- Cannot be disabled, ensuring critical audit trails.
- Logs are immutable and retained for at least 400 days by default.
Memory trick: Required bucket secures the audit trail.
Cloud Logging Log Sinks
Flip cardCloud Logging log sinks allow you to route logs from Cloud Logging to supported destinations like Cloud Storage, BigQuery, or Pub/Sub for storage, analysis, or integration with other systems. Sinks can be configured at the project, folder, or organization level.
- Centralizes logs from multiple sources.
- Supports various destinations for different use cases.
- Organization-level sinks apply to all projects within the organization.
Memory trick: Logs funnel into storage for compliance.
Web Security Scanner (WSS)
Flip cardA Google Cloud service that automatically scans public and private web applications for common vulnerabilities such as XSS, SQL injection, and mixed content issues.
- Automated DAST (Dynamic Application Security Testing).
- Detects common web vulnerabilities.
- Integrates with Security Command Center.
- Can be incorporated into CI/CD pipelines.
Memory trick: Web Security Scanner scans the web, so no bad code gets through the web.
Artifact Analysis for Vulnerability Scanning
Flip cardArtifact Analysis is a service that provides metadata management and vulnerability scanning for software artifacts, including container images, stored in Google Cloud's registries.
- Scans container images for known vulnerabilities (CVEs)
- Integrates into CI/CD pipelines
- Supports policy enforcement before deployment
Memory trick: Analyze the Artifact before it ships!
Cloud Monitoring MQL for Alerts
Flip cardMonitoring Query Language (MQL) in Cloud Monitoring provides a powerful and flexible way to define alert conditions. It allows for complex data transformations, aggregations, filtering by labels, and thresholding on metrics, enabling precise alerting on specific patterns.
- Advanced querying for metrics.
- Supports complex aggregations and filtering.
- Ideal for precise, rate-based alerting.
Memory trick: MQL writes the rules for smart alerts.
Workload Identity (GKE)
Flip cardWorkload Identity allows applications running in Google Kubernetes Engine (GKE) to authenticate to Google Cloud services as a Google Cloud service account, without needing to store or manage service account keys.
- Eliminates the need for service account keys in pods.
- Maps Kubernetes service accounts to Google Cloud service accounts.
- Enhances security by using short-lived credentials.
Memory trick: GKE's Identity is Keyless.
Certificate Authority Service (CAS)
Flip cardA highly available and scalable Google Cloud service for managing private Certificate Authorities (CAs) and issuing X.509 certificates to secure internal services and external applications.
- Operates private CAs without infrastructure management.
- Integrates with other Google Cloud services (e.g., GKE, Load Balancers).
- Supports certificate lifecycle management (issuance, revocation, renewal).
Memory trick: CAS: Your Cloud Certificate Factory.
Access Transparency
Flip cardA Google Cloud service that provides near real-time audit logs of administrative actions taken by Google Cloud personnel when accessing customer data or configurations.
- Logs include Google employee ID, justification, and accessed resources.
- Helps meet stringent regulatory compliance requirements.
- Complements Access Approval by providing visibility after approval.
Memory trick: Access Transparency is like a 'Security Camera' on Google's side, recording every interaction with your data.
Binary Authorization Attestations
Flip cardDigital signatures or assertions made by trusted authorities (attestors) about a container image, which Binary Authorization uses to enforce deployment policies.
- Crucial for software supply chain security.
- Verifies image integrity and compliance before deployment.
- Attestors can be security teams, CI/CD systems, vulnerability scanners.
Memory trick: Binary Auth demands a signed 'permission slip' before the container can launch.
Principle of Least Privilege
Flip cardA security concept in which a user or entity is given only the minimum levels of access or permissions needed to perform its job function.
- Minimizes the attack surface.
- Reduces the impact of a security breach.
- Requires careful access management.
Memory trick: Grant only the 'key' needed, not the whole 'ring'.