Google Cloud Digital LeaderGeneral knowledge of Google CloudHard

A multinational corporation is implementing a zero-trust security model across its Google Cloud environment. They need to ensure that every request to a resource, whether from inside or outside their network, is authenticated and authorized based on the identity of the user or service and the context of the request. Which Google Cloud service is fundamental to enforcing this fine-grained, identity-based access control?

  1. ACloud DNS
  2. BCloud VPN
  3. CCloud Firewall
  4. DIdentity and Access Management (IAM)
Show answer & explanation

Correct answer: D. Identity and Access Management (IAM)

Identity and Access Management (IAM) is the cornerstone of Google Cloud's security model for identity-based access control. It allows administrators to define who (identities) can do what (roles) on which resources, which is essential for implementing a zero-trust model where every request is authenticated and authorized.

Why the other options are wrong

  • A. Cloud DNS is a domain name system service and has no role in access control or zero-trust implementation.
  • B. Cloud VPN provides secure network connectivity, not fine-grained identity-based access control to resources.
  • C. Cloud Firewall controls network traffic based on IP addresses and ports, but doesn't provide identity-based authorization at the resource level.

Google Cloud Identity and Access Management (IAM)

Google Cloud IAM allows administrators to define who has what access to which resources, enabling fine-grained, identity-based access control crucial for security models like zero-trust.

  • Defines 'who' (identity) can do 'what' (role) on 'which' (resource).
  • Essential for fine-grained access control.
  • Core component of zero-trust security.
  • Manages permissions for users, groups, and service accounts.

Memory trick: Zero-Trust means 'Never trust, always verify' with IAM as your bouncer.

More General knowledge of Google Cloud questions