Professional Cloud Security Engineer flashcards
137 free flashcards. Tap a card to flip it.
Cloud SQL Client Role
Flip cardAn IAM role (`roles/cloudsql.client`) that grants permissions to connect to a Cloud SQL instance and perform client-side operations, often used for applications needing to interact with databases.
- Allows connection to Cloud SQL instances.
- Requires in-database permissions for specific database operations.
- Example of least privilege for application database access.
Memory trick: Client connects, Admin manages, Editor edits, Owner owns.
Access Transparency (Audit Proof)
Flip cardA Google Cloud service that generates detailed, immutable audit logs of Google Cloud personnel's administrative access to customer data and configurations, including identity and explicit justification.
- Provides auditable proof of Google's internal access.
- Complements Access Approval by logging *after* consent.
- Crucial for demonstrating 'no unauthorized access' to regulators.
Memory trick: Access Approval is the 'Gatekeeper', and Access Transparency is the 'Security Camera' that watches the gatekeeper.
Short-Lived Service Account Credentials
Flip cardTemporary, time-bound access tokens generated for a Google Cloud service account, used to access Google Cloud resources without needing long-lived service account keys.
- Generated via the `generateAccessToken` API.
- Ideal for CI/CD, ephemeral workloads, and enhanced security.
- Reduces the risk associated with compromised long-lived keys.
Memory trick: Generate Access Token, Go Quickly.
Organization Policy Service
Flip cardA service that allows Google Cloud administrators to programmatically control their organization's cloud resources, enabling centralized governance and compliance.
- Enforces policies across projects and folders.
- Supports predefined and custom constraints.
- Helps achieve compliance and security objectives.
Memory trick: Organization's Policies: The Boss of All Projects.
Google Cloud Admin Activity Logs
Flip cardAudit logs that record API calls or other actions that modify the configuration or metadata of resources, such as creating VMs, setting IAM policies, or modifying network configurations.
- Always enabled by default and cannot be disabled.
- Includes operations like 'create', 'update', 'delete'.
- Crucial for auditing administrative changes and security incidents.
Memory trick: Admin acts, Data flows, System hums, Policy protects.
Workload Identity (GCP)
Flip cardA feature that allows workloads running on Google Kubernetes Engine (GKE) or Compute Engine to securely access Google Cloud services by acting as a Google Cloud service account, eliminating the need for service account key files.
- Provides short-lived, automatically rotated credentials.
- Enhances security by removing long-lived key files.
- Integrates Kubernetes service accounts with Google Cloud service accounts.
Memory trick: Workload Identity 'retires' old keys for 'fresh' ones, automatically.
API Key Restrictions
Flip cardAPI keys are simple credential tokens used to authenticate to certain Google Cloud APIs. They should always be restricted by application type (e.g., HTTP referrer, Android/iOS app) and specific API services to limit their scope.
- Identifies the calling project/application.
- Must be restricted by HTTP referrer/app bundle.
- Should be limited to specific API services.
Memory trick: Restrict your API keys to keep them safe.
Organization Policy Custom Constraints
Flip cardAn extension of Google Cloud's Organization Policy Service that allows administrators to define highly specific, custom rules for resource configurations beyond the predefined constraints.
- Provides fine-grained control over resource properties.
- Enables enforcement of unique organizational compliance requirements.
- Can be used to prevent creation of non-compliant resources.
Memory trick: Custom Org Policies are like 'Tailored Guards' – they enforce your unique rules before anything non-compliant can even appear.
Access Approval
Flip cardAccess Approval allows Google Cloud customers to explicitly approve or deny Google personnel access to their data and configurations, providing an auditable workflow for sensitive operations.
- Requires customer approval for Google personnel access.
- Generates audit logs of all access requests and decisions.
- Enhances control and transparency over data access by Google.
Memory trick: Access Approval is like a 'gatekeeper' for Google, only opening with your 'OK'.
Cloud Asset Inventory (IAM Auditing)
Flip cardCloud Asset Inventory provides a centralized inventory service for Google Cloud assets and their associated metadata, including IAM policies, making it suitable for security auditing and compliance.
- Centralized view of all cloud assets.
- Exports IAM policies for analysis.
- Supports large-scale auditing and compliance checks.
Memory trick: Inventory assets to audit roles efficiently.
Workforce Identity Federation
Flip cardA Google Cloud service that allows employees to use their existing external identity provider (IdP) to access Google Cloud resources, without synchronizing user data to Google Cloud.
- Connects external IdPs (e.g., Okta, Azure AD, Active Directory) to Google Cloud.
- Users authenticate with their IdP, then obtain temporary Google Cloud credentials.
- Ideal for managing employee access to Google Cloud without direct user synchronization.
Memory trick: Federation Fuses Firms' Identities.
IAM Conditions (Time-based)
Flip cardA Google Cloud IAM feature that allows you to define conditional role bindings, where access is granted only if certain criteria, such as specific time windows, are met.
- Uses Common Expression Language (CEL) for condition expressions.
- Can restrict access based on date, time, IP address, resource tags, etc.
- Applied directly to an IAM policy binding.
Memory trick: Conditions Control Current Clock.
Binary Authorization
Flip cardA Google Cloud service that provides software supply chain security by enforcing deployment policies on container images and VM images.
- Prevents deployment of unauthorized or non-compliant binaries.
- Integrates with CI/CD pipelines and vulnerability scanners.
- Supports attestation by trusted authorities.
Memory trick: Binary Auth checks the image's passport before it can fly.
Organization Policies
Flip cardA Google Cloud service that allows administrators to programmatically control Google Cloud resources across an entire organization, defining guardrails and restrictions.
- Applied at the Organization, Folder, or Project level.
- Uses constraints to enforce rules (e.g., `list_allowed_values`, `true_false`).
- Essential for central governance and compliance.
Memory trick: Organization Policies Orchestrate Overall Protection.
Google Cloud Access Approval
Flip cardAccess Approval allows customers to explicitly approve or deny Google support and engineering access to their Google Cloud data, generating an audit trail for compliance.
- Mandates customer approval for Google access.
- Provides an immutable audit trail.
- Crucial for highly regulated industries like finance.
Memory trick: Approve access for Google, or it's a no-go.
Essential Contacts
Flip cardA Google Cloud service that allows organizations to define who should receive critical notifications from Google Cloud regarding various operational, security, and compliance-related events.
- Centralized management of notification recipients.
- Supports multiple contact types (e.g., security, legal, billing).
- Ensures critical information reaches the right stakeholders.
Memory trick: Essential Contacts: Your Cloud's Emergency Call List.
Security Command Center
Flip cardA Google Cloud security management and data risk platform that helps prevent, detect, and respond to threats across an organization's Google Cloud assets.
- Provides a centralized dashboard for security posture.
- Aggregates findings from various security sources.
- Helps identify vulnerabilities, misconfigurations, and threats.
Memory trick: Security Command Center is the 'CISO's Control Panel', showing all cloud security intel in one place.
Google Cloud Identity Platform
Flip cardIdentity Platform is a customer identity and access management (CIAM) service that allows developers to add Google-grade authentication to their applications, supporting various sign-in methods.
- Supports social, email/password, SAML/OIDC authentication.
- Designed for consumer-facing applications.
- Integrates with Google Cloud backend services.
Memory trick: Identity Platform is where customers sign in.
API Key Restrictions (Organization Policy)
Flip cardEnforcing rules on API keys, such as allowed IP addresses or API services, across an organization using Organization Policy Constraints.
- Provides centralized control over API key security.
- Prevents creation of overly permissive API keys.
- Enforced at the organization, folder, or project level.
Memory trick: Org Policy is the 'bouncer' for 'API keys', checking their 'ID' and 'destination'.
VPC Firewall Rules
Flip cardStateful firewall rules in Google Cloud's Virtual Private Cloud (VPC) that allow or deny traffic to and from VM instances based on various criteria such as IP addresses, ports, protocols, and service accounts.
- Applied at the instance level.
- Stateful (return traffic is automatically allowed).
- Supports ingress and egress rules with priority.
Memory trick: VPC Firewalls: Your Network's Traffic Cops.
Pub/Sub Granular IAM
Flip cardGoogle Cloud Pub/Sub allows fine-grained IAM roles to be granted at the topic or subscription level, ensuring that service accounts or users only have the exact permissions needed.
- Roles can be granted on individual topics/subscriptions.
- Specific roles: `publisher`, `subscriber`, `viewer`, `editor`.
- Essential for least privilege in messaging architectures.
Memory trick: Give topics their own specific roles.
Google Cloud Resource Hierarchy (Projects/Folders)
Flip cardThe hierarchical structure of Google Cloud resources (Organization > Folders > Projects > Resources) that provides the fundamental isolation boundaries for billing, IAM, and resource management.
- Projects are the basic unit of resource management and billing.
- Projects provide strong isolation boundaries for network and IAM.
- Folders group projects for policy inheritance and management.
Memory trick: Projects & Folders: Cloud's Apartment Building.
Cloud Audit Logs: Admin Activity
Flip cardAdmin Activity logs record API calls or other administrative actions that modify the configuration or metadata of resources, always enabled and immutable.
- Tracks resource creation/deletion/modification.
- Always enabled by default.
- Immutable audit trail for compliance.
Memory trick: Admin logs track who changed what.
Resource Manager Folders & IAM Inheritance
Flip cardFolders in Google Cloud's Resource Manager allow hierarchical grouping of projects, enabling IAM policies to be applied at a higher level and inherited by all contained resources.
- Provides logical grouping for projects.
- Facilitates centralized management of IAM policies.
- Enables delegation of administrative responsibilities efficiently.
Memory trick: Folders are like filing cabinets, and IAM is the key to each drawer.
Workload Identity (GKE)
Flip cardWorkload Identity allows applications running in Google Kubernetes Engine (GKE) to authenticate to Google Cloud services as a Google Cloud service account, without needing to store or manage service account keys.
- Eliminates the need for service account keys in pods.
- Maps Kubernetes service accounts to Google Cloud service accounts.
- Enhances security by using short-lived credentials.
Memory trick: GKE's Identity is Keyless.
Cloud SQL IAM Database Authentication
Flip cardCloud SQL IAM database authentication allows users and service accounts to connect to Cloud SQL instances using their IAM identity rather than traditional database usernames and passwords.
- Eliminates static database credentials.
- Leverages IAM for database access control.
- Supports both user and service account authentication.
Memory trick: IAM authenticates to SQL, no secrets needed.
Secret Manager
Flip cardA Google Cloud service for securely storing, managing, and accessing sensitive data (secrets) such as API keys, passwords, and certificates.
- Offers strong encryption at rest and in transit.
- Provides fine-grained access control via IAM.
- Includes automatic versioning and detailed audit logging.
Memory trick: Secret Manager is the 'Vault' for your application's most sensitive keys and passwords.
CMEK with Cloud KMS & Cloud Storage
Flip cardCustomer-Managed Encryption Keys (CMEK) leverage Cloud KMS to create, manage, and rotate encryption keys used by services like Cloud Storage for data at rest encryption, providing enhanced control over cryptographic material.
- Customer controls the encryption key lifecycle.
- Cloud KMS provides key management, rotation, and access control.
- Cloud Storage uses CMEK for data at rest encryption instead of Google-managed keys.
Memory trick: KMS for Keys, Storage for Data.
Organization Policy for API Keys
Flip cardUsing Google Cloud Organization Policies to enforce specific security constraints on API keys, such as requiring HTTP referrer restrictions.
- Enforces rules across the organization, folders, or projects.
- Uses constraints like `apikeys.allowedRestrictions`.
- Prevents creation or update of non-compliant API keys.
Memory trick: Organization Policies Orchestrate Perfect API Key Protection.
Resource Manager
Flip cardA Google Cloud service that allows you to logically group and manage Google Cloud projects, folders, and organizations in a hierarchical structure.
- Forms the foundation for IAM and Organization Policy inheritance.
- Enables centralized management of resources.
- Mirrors real-world organizational structures.
Memory trick: Resource Manager builds the 'family tree' for all your cloud assets.
Organization Policy: Resource Locations
Flip cardA Google Cloud Organization Policy constraint (`constraints/gcp.resourceLocations`) that restricts the geographical locations where an organization's cloud resources can be created, ensuring data residency compliance.
- Applies at Organization, Folder, or Project level.
- Prevents resource creation outside specified regions/zones.
- Critical for data residency and regulatory compliance.
Memory trick: Org Policy Location: The Cloud's Geofence.
Google Cloud Directory Sync (GCDS)
Flip cardGCDS is a free tool that synchronizes users, groups, and organizational structures from an existing LDAP directory (like Active Directory) to Google Cloud Identity.
- Connects on-premises LDAP to Cloud Identity.
- Allows granular filtering of OUs and attributes.
- Supports scheduled synchronization.
Memory trick: GCDS syncs your old AD to the new cloud.
Hierarchical Firewall Policies
Flip cardA Google Cloud capability that allows granular firewall rules to be defined and enforced at the organization or folder level, applying to all projects and resources beneath them.
- Enables centralized network security management.
- Rules inherit down the resource hierarchy.
- Can override or complement VPC firewall rules.
Memory trick: Hierarchical Firewalls are the 'Master Plan' for network security, defining rules from the top down.
Access Approval & Access Transparency
Flip cardAccess Approval allows customers to approve or deny Google personnel access to their data, while Access Transparency provides logs of Google's administrative actions on customer resources.
- Access Approval provides explicit control over Google access.
- Access Transparency offers immutable logs of Google's actions.
- Crucial for highly regulated industries requiring auditability.
Memory trick: Approve and See: Google's Data Journey.
Cloud Audit Logs - Admin Activity
Flip cardA type of Google Cloud Audit Log that records administrative actions and metadata changes to Google Cloud resources.
- Always enabled by default and cannot be disabled.
- Records operations that modify resource configuration or metadata.
- Includes details like who performed the action, when, and from where.
Memory trick: Admin Activity Alters All A-OK.
Cloud Armor
Flip cardA Google Cloud service that provides DDoS protection and Web Application Firewall (WAF) capabilities to safeguard public-facing applications and APIs from various network and application layer attacks.
- Protects against DDoS attacks (L3/L4 and L7).
- Offers WAF rules for common web vulnerabilities (e.g., SQLi, XSS).
- Integrates with Google Cloud Load Balancing.
Memory trick: Cloud Armor: Your Web's Bouncer.
API Key IP Restrictions
Flip cardA security feature for Google Cloud API keys that limits their usability to requests originating from specified IP addresses or CIDR ranges.
- Configured directly on the API key.
- Enhances security by preventing unauthorized use from other networks.
- Can be combined with HTTP referrer and Android/iOS app restrictions.
Memory trick: Restrict IP, Secure API Key.
Custom Role (Fine-grained BigQuery)
Flip cardCustom roles allow defining specific sets of permissions tailored to exact requirements, enabling fine-grained access control to Google Cloud resources like BigQuery datasets and tables.
- Define specific permissions (e.g., `bigquery.tables.create`).
- Bind at the lowest possible resource level (e.g., dataset).
- Adheres to the principle of least privilege.
Memory trick: Custom roles bind specific powers to specific data.
Organization Policy Hierarchy & Overrides
Flip cardOrganization policies are inherited downwards through the resource hierarchy (Organization > Folders > Projects), with policies at lower levels able to override or merge with policies from higher levels.
- Policies are inherited by default.
- Parent policies can be overridden or merged by child policies.
- Different constraint types (boolean, list) have different override behaviors (e.g., boolean 'false' can override 'true').
Memory trick: The family rules (Org Policy) are strict, but specific branches (Folders) can get special permission.
Google-managed SSL Certificates
Flip cardA feature within Google Cloud Load Balancing that automatically provisions and renews public SSL/TLS certificates for external-facing applications.
- Handles certificate lifecycle (provisioning, renewal, revocation).
- Free of charge and integrates seamlessly with Cloud Load Balancing.
- Eliminates the need for manual certificate management.
Memory trick: Google-managed SSL is like a self-driving car for your certificates.
Pub/Sub Publisher Role
Flip cardAn IAM predefined role that grants permissions to publish messages to Google Cloud Pub/Sub topics.
- Specifically designed for publishing messages.
- Adheres to the principle of least privilege for message producers.
- Does not grant permissions to create topics, subscribe, or view messages.
Memory trick: Publisher Posts Pub/Sub Properly.
Organization Policy Constraints (Custom)
Flip cardRules defined within Google Cloud Organization Policy Service that enforce restrictions on how resources can be configured, including what permissions can be included in custom IAM roles.
- Applied at organization, folder, or project level.
- Can enforce allowlists or denylists for specific resource properties or IAM permissions.
- Crucial for enforcing security and compliance guardrails across the organization.
Memory trick: Org Policies are the 'guardrails' for 'custom roles'.
gcloud IAM Policy Auditing
Flip cardUsing `gcloud` commands with `flatten` and `filter` to inspect and audit IAM policy bindings for specific roles or members within a Google Cloud project or organization.
- `get-iam-policy` retrieves the current policy.
- `--flatten` expands nested structures for easier filtering.
- `--filter` allows precise querying of results based on fields and values.
Memory trick: Get Policy, Filter Roles, Find Violations.
Organization Policy Constraint (IAM)
Flip cardOrganization Policy Constraints allow administrators to define and enforce rules (constraints) across all resources in a Google Cloud organization, such as restricting specific IAM role assignments.
- Enforces rules organization-wide.
- Can prevent specific IAM role grants.
- Applies to new and existing resources.
Memory trick: Organization policies constrain what roles can be granted.
Principle of Least Privilege (PoLP)
Flip cardThe security principle that states users, programs, or processes should be granted only the minimum necessary permissions to perform their legitimate functions.
- Reduces attack surface.
- Limits impact of compromise.
- Achieved with granular roles (custom or specific predefined).
Memory trick: Least privilege is the key to a secure cloud.
Private Service Connect for Network Integration
Flip cardPrivate Service Connect for network integration allows a consumer VPC to steer all or specific traffic through a producer VPC (e.g., an NVA VPC) for centralized network services like inspection or NAT.
- Enables centralized network services (e.g., NVA, NAT) in a separate VPC.
- Traffic from consumer VPC is routed through producer VPC for processing.
- Uses service attachments and endpoints, combined with custom routes, for traffic steering.
Memory trick: PSC Network Integration: Your traffic takes a mandatory detour through the NVA checkpoint.
Global External HTTP(S) LB, CDN, & Cloud Armor
Flip cardThis combination provides a robust solution for globally distributed web applications, offering performance, availability, and security.
- Global External HTTP(S) Load Balancer for global traffic distribution and low latency.
- Cloud CDN for caching static content closer to users, improving performance.
- Cloud Armor for DDoS protection and Web Application Firewall (WAF) capabilities.
Memory trick: Global LB routes, CDN speeds, Armor protects.
Dedicated Interconnect Redundancy
Flip cardDedicated Interconnect offers direct, private connections to Google Cloud. For redundancy, multiple connections across different physical paths, metros, and edge availability domains are recommended.
- Provides private, high-bandwidth (10/100 Gbps) connections.
- Requires physical presence at a Google-supported colocation facility.
- Redundancy achieved by multiple connections in different metros/edge domains.
Memory trick: Dedicated Interconnect: Direct, Data-intensive, Dependable.
Cloud Interconnect Redundancy
Flip cardAchieving highly available Cloud Interconnect involves configuring redundant connections across different physical paths and/or metropolitan areas.
- Dedicated or Partner Interconnect options
- Redundant connections for high availability
- Geographically diverse connections for disaster recovery
Memory trick: Reliable connections need multiple paths, like a strong rope with many strands.
Cloud Interconnect (Dedicated)
Flip cardDedicated Interconnect provides direct physical connections between an on-premises network and Google Cloud, offering high bandwidth and low latency.
- Direct physical connection
- Bypasses public internet
- Supports VLAN attachments for segmentation
Memory trick: Private connections are like a superhighway for data, not a bumpy backroad.
GKE Network Policies
Flip cardGKE Network Policies enable granular control over network communication between pods within a GKE cluster and between pods and external endpoints.
- Pod-level traffic control
- Uses Kubernetes NetworkPolicy API
- Configurable for ingress and egress
Memory trick: GKE pods need policies to guard their traffic flow.
GCP Firewall Rule Components
Flip cardGoogle Cloud firewall rules control traffic to and from VM instances based on direction, protocol, ports, sources/targets, and network.
- Direction (Ingress/Egress)
- Protocol and Port
- Target (tags/service accounts)
- Source/Destination (IP ranges/tags/service accounts)
Memory trick: Firewall rules: Who comes in, who goes out, where they go, and what they carry.
VPC Service Controls Audit Logs
Flip cardVPC Service Controls generates audit logs that record policy violations, including 'ACCESS_DENIED' events when a request attempts to cross a perimeter boundary unlawfully.
- Logs 'ACCESS_DENIED' events for perimeter violations.
- Provides details about the violating request and its context.
- Crucial for monitoring and troubleshooting VPC Service Controls deployments.
Memory trick: Perimeter logs are the security guard's report.
Cloud VPN
Flip cardCloud VPN allows you to securely connect your on-premises network to your Google Cloud Virtual Private Cloud (VPC) network through an IPsec VPN connection.
- Uses IPsec VPN for encryption and security.
- Connects over the public internet.
- Supports high availability with redundant tunnels.
Memory trick: VPN is like a private tunnel for your data through the public internet.
VPC Flow Logs
Flip cardVPC Flow Logs record a sample of network flows sent from and received by VM instances, providing visibility into network traffic patterns.
- Captures source/destination IP, port, protocol, bytes, packets.
- Can be configured to log accepted, denied, or all traffic.
- Useful for network monitoring, forensics, and security analysis.
Memory trick: Flow Logs show you the 'who, what, where' of your network traffic.
Cloud DNS Peering Zones
Flip cardCloud DNS peering zones enable DNS resolution from a VPC network to the private zones configured in a peered VPC network, facilitating consistent internal DNS across complex environments.
- Cross-VPC private DNS resolution
- Works with VPC Network Peering
- Simplifies DNS management in multi-VPC setups
Memory trick: Peering zones let VPCs share their secret phone books.
Multiple VPC Networks
Flip cardCreating distinct Virtual Private Cloud (VPC) networks within a Google Cloud project or organization.
- Provides strong network isolation by default
- Each VPC has its own routing table and firewall rules
- No implicit connectivity between separate VPCs
Memory trick: Build strong walls between your networks.
Network Intelligence Center
Flip cardNetwork Intelligence Center is a suite of network monitoring, diagnostics, and optimization capabilities in Google Cloud.
- Centralized network visibility
- Firewall Insights feature
- Network Topology visualization
Memory trick: Seeing the network's brain helps secure its every move.
Cloud CDN
Flip cardCloud CDN leverages Google's global edge network to cache content close to users, reducing latency and offloading origin servers.
- Global content caching
- SSL/TLS termination at edge
- Reduces latency and origin load
Memory trick: Faster web means content at the edge, served with a secure smile.
GCP Implicit Firewall Rules
Flip cardEvery Google Cloud VPC network has two implicit firewall rules: an ingress deny all and an egress allow all.
- Implicit ingress deny: blocks all incoming connections by default.
- Implicit egress allow: permits all outgoing connections by default.
- User-created rules override implicit rules based on priority and specificity.
Memory trick: Ingress is implicitly denied; you must explicitly invite.