Professional Cloud ArchitectDesign and plan a cloud solution architectureHard
A healthcare provider is migrating sensitive patient data to Google Cloud. The data must be encrypted at rest and in transit, and access must be restricted based on the principle of least privilege. The provider also needs to demonstrate compliance with HIPAA regulations. Which combination of Google Cloud security features should be implemented?
- ACustomer-Managed Encryption Keys (CMEK) for Cloud Storage and databases, VPC Service Controls for data exfiltration prevention, and Cloud IAM for granular access control.
- BGoogle-Managed Encryption Keys (GMEK) for all data, Security Command Center for vulnerability scanning, and Shared VPC for network isolation.
- CCloud Key Management Service (KMS) for all encryption, Cloud Armor for DDoS protection, and Cloud Audit Logs for compliance reporting.
- DCustomer-Supplied Encryption Keys (CSEK) for Cloud Storage, Identity-Aware Proxy (IAP) for application access, and Cloud DLP for data scanning.
Show answer & explanationAnswer & explanation
Correct answer: A. Customer-Managed Encryption Keys (CMEK) for Cloud Storage and databases, VPC Service Controls for data exfiltration prevention, and Cloud IAM for granular access control.
CMEK provides customer control over encryption keys, VPC Service Controls creates a security perimeter against data exfiltration, and Cloud IAM enforces least privilege. This combination directly addresses encryption, access control, and compliance needs for sensitive data like HIPAA.
Why the other options are wrong
- B. GMEK is standard but less control than CMEK for sensitive data. Security Command Center and Shared VPC are good, but VPC Service Controls offers more direct data exfiltration protection which is critical for HIPAA compliance.
- C. KMS is the underlying service for CMEK, but KMS alone doesn't define the entire security posture. Cloud Armor is for DDoS, not primary data access/exfiltration control. Audit Logs are for reporting, not direct prevention or access control mechanisms for data at rest/in transit.
- D. CSEK requires the customer to manage keys entirely, which can be complex. While IAP and DLP are useful, VPC Service Controls is a stronger perimeter control. HIPAA compliance isn't solely met by these.
VPC Service Controls
A Google Cloud feature that creates security perimeters around sensitive data to mitigate data exfiltration risks.
- Creates security perimeters for Google Cloud services
- Restricts data movement between perimeters and outside
- Prevents unauthorized access from outside the perimeter
- Crucial for compliance (e.g., HIPAA, PCI DSS)
Memory trick: VPC Service Controls protect sensitive data like a fortress wall, and CMEK guards the keys.