Professional Cloud ArchitectDesign and plan a cloud solution architectureHard

A large pharmaceutical company is migrating its research data, including clinical trial results and genomic sequences, to Google Cloud. This data is critical, highly sensitive, and subject to strict regulatory compliance (e.g., HIPAA, GDPR). The company needs to ensure that data access is restricted to authorized personnel only, and that any attempt to exfiltrate data outside of approved perimeters is prevented. They also want to isolate their sensitive data processing environments from the public internet. Which security control combination should they implement?

  1. AVPC Service Controls and Context-Aware Access
  2. BVPC Service Controls and Shared VPC
  3. CCloud Armor and Cloud Data Loss Prevention (DLP)
  4. DIdentity and Access Management (IAM) and Security Command Center
Show answer & explanation

Correct answer: A. VPC Service Controls and Context-Aware Access

VPC Service Controls create a security perimeter around sensitive data resources, preventing data exfiltration and isolating them from unauthorized networks. Context-Aware Access (part of BeyondCorp Enterprise) then provides granular access control based on user identity, device posture, and location, ensuring only authorized personnel with compliant devices can access the data within the perimeter.

Why the other options are wrong

  • B. Shared VPC is a networking construct for sharing VPCs, not a security control for data exfiltration prevention or context-aware access.
  • C. Cloud Armor is a DDoS and WAF service, primarily for protecting applications from external threats. Cloud DLP helps discover and redact sensitive data, but neither directly prevents exfiltration at the network perimeter or provides context-aware access control for users.
  • D. IAM manages access to resources, and Security Command Center provides security insights, but neither directly prevents data exfiltration or creates a strong perimeter against unauthorized access from outside.

VPC Service Controls + Context-Aware Access

A powerful combination of Google Cloud security controls to create secure perimeters around sensitive data (VPC Service Controls) and enforce granular access based on user context (Context-Aware Access).

  • VPC Service Controls prevent data exfiltration and isolate services.
  • Context-Aware Access (BeyondCorp) provides identity- and context-based authorization.
  • Ideal for highly regulated industries and sensitive data workloads.

Memory trick: Perimeters keep data in, Context keeps bad actors out.

More Design and plan a cloud solution architecture questions