Google Cloud Digital LeaderDigital transformation with Google CloudMedium

A regulatory body mandates that all financial transaction data must be encrypted at rest and in transit, and access to this data must be strictly controlled based on the principle of least privilege. The company uses Google Cloud for its data processing. Which Google Cloud service is fundamental for implementing and enforcing these security and access control requirements?

  1. ACloud Monitoring.
  2. BCloud CDN.
  3. CCloud IAM.
  4. DCloud Load Balancing.
Show answer & explanation

Correct answer: C. Cloud IAM.

Cloud IAM (Identity and Access Management) is fundamental for enforcing the principle of least privilege by defining who has what access to which resources, and it works in conjunction with encryption services to secure data.

Why the other options are wrong

  • A. Cloud Monitoring collects metrics and logs, useful for observing security but not for directly enforcing access control or encryption.
  • B. Cloud CDN is for content delivery, not security or access control.
  • D. Cloud Load Balancing distributes traffic, which is a networking function, not for managing access to data.

Cloud IAM

Google Cloud Identity and Access Management (IAM) enables you to manage access control by defining who (identity) has what access (role) for which resource.

  • Grants granular permissions based on the principle of least privilege.
  • Integrates with other Google Cloud services.
  • Uses roles to define collections of permissions.
  • Crucial for security and compliance.

Memory trick: IAM is the 'bouncer' at the cloud club, deciding WHO gets IN.

More Digital transformation with Google Cloud questions