Google Cloud Digital LeaderGeneral knowledge of Google CloudMedium
A multinational corporation is implementing a zero-trust security model across its Google Cloud environment. They need to ensure that only authorized individuals and services have the minimum necessary permissions to access specific resources, and these permissions should be dynamically granted and revoked. Which Google Cloud service is fundamental to achieving this granular access control?
- AGoogle Cloud Security Command Center
- BGoogle Cloud IAM
- CGoogle Cloud VPN
- DGoogle Cloud Firewall Rules
Show answer & explanationAnswer & explanation
Correct answer: B. Google Cloud IAM
Google Cloud Identity and Access Management (IAM) is the core service for defining and managing granular permissions for users and services, which is fundamental to implementing a zero-trust model.
Why the other options are wrong
- A. Security Command Center is for security posture management and threat detection, not for defining access policies.
- C. Cloud VPN creates secure connections between networks, but doesn't manage individual user or service permissions.
- D. Firewall rules control network traffic flow, which is part of security but doesn't define 'who' has 'what' permissions on 'resources'.
Google Cloud IAM
Google Cloud Identity and Access Management (IAM) enables you to manage access control by defining who (identity) has what access (role) for which resource.
- Supports the principle of least privilege.
- Grants granular permissions at project, folder, and organization levels.
- Integrates with Google identities and external identity providers.
- Allows custom roles for specific permission sets.
Memory trick: To 'I'dentify 'A'ccess 'M'atrices, use 'IAM' for zero trust.