Professional Cloud Security Engineer flashcards
137 free flashcards. Tap a card to flip it.
Private Service Connect (PSC)
Flip cardPrivate Service Connect (PSC) allows consumers to privately access Google-managed services and services deployed by other VPCs, using internal IP addresses and without traversing the internet.
- Enables private access to services across VPCs/projects.
- Uses internal IP addresses, no public internet.
- Supports both consumer and producer side configurations.
Memory trick: PSC: Private, Secure, Connected; services to services.
Network Intelligence Center (Firewall Insights)
Flip cardNetwork Intelligence Center's Firewall Insights provides analytics and insights into Google Cloud firewall rules, helping identify optimization opportunities and potential security risks.
- Identifies unused, shadowed, and overly permissive firewall rules.
- Helps understand the impact of firewall rules.
- Centralizes visibility for network security posture.
Memory trick: NIC is your network's 'eyes and brain' for security.
Cloud DNS Private Zones & Peering
Flip cardPrivate DNS zones in Google Cloud for internal-only resolution, which can be shared across VPCs using DNS peering.
- Resolves internal domain names within VPC networks
- DNS Peering allows private zones to be queried from other peered VPCs
- Supports hybrid cloud DNS resolution when combined with Cloud VPN/Interconnect
Memory trick: Your private DNS, everywhere, securely.
GCP Firewall Rules
Flip cardRules that allow or deny traffic to and from Google Cloud instances based on specified configurations.
- Operate at the VPC network level
- Can be configured for ingress (inbound) or egress (outbound) traffic
- Parameters include IP ranges, protocols, ports, and network tags/service accounts
Memory trick: Traffic lights for your cloud network.
Private Service Connect (Endpoints)
Flip cardPrivate Service Connect (PSC) allows private access to services deployed in other VPC networks (producer VPCs) from a consumer VPC, using internal IP addresses and avoiding IP range conflicts.
- Enables private service consumption across different VPCs/projects.
- Supports overlapping IP addresses between consumer and producer VPCs.
- Does not require VPC Network Peering and avoids public internet.
Memory trick: PSC endpoints are private doors between specific services in different VPCs.
Private Service Connect (Published Services)
Flip cardGoogle Cloud service enabling service producers to publish services to consumers in different VPC networks using private IP addresses.
- Provides private connectivity between VPC networks for service consumption
- Offers granular control over service access (consumer projects/networks)
- Supports high throughput and low latency, without traversing the public internet
Memory trick: Connect services privately, fast, and controlled.
Cloud Interconnect (Dedicated)
Flip cardDedicated Interconnect provides direct physical connections between an on-premises network and Google Cloud, offering high bandwidth and low latency.
- Direct physical connection
- Bypasses public internet
- Supports VLAN attachments for segmentation
Memory trick: Private connections are like a superhighway for data, not a bumpy backroad.
GKE Network Policies
Flip cardGKE Network Policies enable granular control over network communication between pods within a GKE cluster and between pods and external endpoints.
- Pod-level traffic control
- Uses Kubernetes NetworkPolicy API
- Configurable for ingress and egress
Memory trick: GKE pods need policies to guard their traffic flow.
GCP Firewall Rule Components
Flip cardGoogle Cloud firewall rules control traffic to and from VM instances based on direction, protocol, ports, sources/targets, and network.
- Direction (Ingress/Egress)
- Protocol and Port
- Target (tags/service accounts)
- Source/Destination (IP ranges/tags/service accounts)
Memory trick: Firewall rules: Who comes in, who goes out, where they go, and what they carry.
VPC Service Controls Audit Logs
Flip cardVPC Service Controls generates audit logs that record policy violations, including 'ACCESS_DENIED' events when a request attempts to cross a perimeter boundary unlawfully.
- Logs 'ACCESS_DENIED' events for perimeter violations.
- Provides details about the violating request and its context.
- Crucial for monitoring and troubleshooting VPC Service Controls deployments.
Memory trick: Perimeter logs are the security guard's report.
Cloud VPN
Flip cardCloud VPN allows you to securely connect your on-premises network to your Google Cloud Virtual Private Cloud (VPC) network through an IPsec VPN connection.
- Uses IPsec VPN for encryption and security.
- Connects over the public internet.
- Supports high availability with redundant tunnels.
Memory trick: VPN is like a private tunnel for your data through the public internet.
Cloud Interconnect
Flip cardCloud Interconnect provides a direct, private connection between your on-premises network and Google Cloud's network.
- Bypasses the public internet
- Offers higher bandwidth and lower latency than VPN over public internet
- Available in two main types: Dedicated and Partner Interconnect
Memory trick: Interconnect: The direct line to the Cloud.
Global External HTTP(S) LB, CDN, & Cloud Armor
Flip cardThis combination provides a robust solution for globally distributed web applications, offering performance, availability, and security.
- Global External HTTP(S) Load Balancer for global traffic distribution and low latency.
- Cloud CDN for caching static content closer to users, improving performance.
- Cloud Armor for DDoS protection and Web Application Firewall (WAF) capabilities.
Memory trick: Global LB routes, CDN speeds, Armor protects.
Dedicated Interconnect Redundancy
Flip cardDedicated Interconnect offers direct, private connections to Google Cloud. For redundancy, multiple connections across different physical paths, metros, and edge availability domains are recommended.
- Provides private, high-bandwidth (10/100 Gbps) connections.
- Requires physical presence at a Google-supported colocation facility.
- Redundancy achieved by multiple connections in different metros/edge domains.
Memory trick: Dedicated Interconnect: Direct, Data-intensive, Dependable.
IP Address Lists (Network Firewall Policies)
Flip cardA feature within Google Cloud Network Firewall Policies that allows defining named collections of IP addresses or CIDR ranges for reusable use in firewall rules.
- Centralizes management of IP addresses.
- Ensures consistency across multiple firewall rules.
- Can be used for both source and destination IP addresses.
Memory trick: IP Address Lists are like a VIP guest list for your firewall, easily updated and shared.
Private Service Connect
Flip cardA Google Cloud networking product that allows private consumption of managed services across VPC networks, ensuring traffic remains within Google's network.
- Enables private connectivity to services (Google-managed, partner, or custom).
- Traffic does not traverse the public internet.
- Supports both service producers and consumers across different organizations.
Memory trick: Private Service Connect, like a secret handshake, links your cloud to another's service, no public eyes allowed.
Organization Policy Constraints
Flip cardOrganization Policy Constraints allow administrators to define guardrails for their Google Cloud resources, enforcing specific behaviors or preventing certain actions across the entire organization or specific parts of it.
- Applied at the Organization, Folder, or Project level.
- Preventative controls, not just reactive auditing.
- Can restrict resource configurations, API usage, and IAM policies.
- Often used to enforce compliance and security best practices.
Memory trick: Organization's Royal Guard: No one gets the Crown without explicit permission!