Professional Cloud ArchitectDesign and plan a cloud solution architectureHard
A large pharmaceutical company is migrating its research data, including clinical trial results and genomic sequences, to Google Cloud. This data is highly sensitive and subject to stringent regulatory compliance (e.g., HIPAA, GDPR). They need to ensure that only authorized users and services can access this data, and that data exfiltration risks are minimized, even from compromised insiders or misconfigured applications. They also require that access from outside their corporate network is restricted and conditional. Which security controls should they implement?
- ACloud Armor and Security Command Center
- BVPC Service Controls and Context-Aware Access
- CShared VPC and Firewall Rules
- DVPC Service Controls and Cloud IAM
Show answer & explanationAnswer & explanation
Correct answer: B. VPC Service Controls and Context-Aware Access
VPC Service Controls create security perimeters around sensitive data and services, preventing data exfiltration. Context-Aware Access integrates with Identity-Aware Proxy (IAP) to enforce granular access based on user attributes and device context (e.g., IP address, device health), fulfilling the requirement for restricted and conditional access from outside the corporate network.
Why the other options are wrong
- A. Cloud Armor is a WAF for DDoS and web application attacks, and Security Command Center is a security management and risk platform; neither directly addresses data exfiltration prevention or contextual external access control at the granular level required.
- C. Shared VPC and Firewall Rules provide network isolation and traffic filtering but do not directly prevent data exfiltration from compromised services or enforce contextual access policies.
- D. VPC Service Controls address data exfiltration, but Cloud IAM alone doesn't provide the 'restricted and conditional access from outside their corporate network' based on context.
VPC Service Controls + Context-Aware Access
A powerful combination for securing sensitive data: VPC Service Controls create security perimeters to prevent data exfiltration, while Context-Aware Access enforces granular, conditional access policies based on user and device context.
- VPC Service Controls: data exfiltration prevention, perimeter security
- Context-Aware Access: conditional access based on user/device context
- Integrates with Identity-Aware Proxy (IAP)
- Ideal for highly sensitive data and strict compliance
Memory trick: Perimeter Guard + Context Check = Fortress Data.