Professional Cloud Security EngineerEnsuring data protectionMedium
A research institution is processing highly sensitive genetic sequence data in BigQuery. Due to stringent privacy regulations, they must ensure that this data never leaves the Google Cloud network perimeter and that all access to the BigQuery datasets and any associated Cloud Storage buckets is restricted to authorized endpoints within a defined VPC network. Additionally, they need to prevent data exfiltration to unauthorized external destinations. Which Google Cloud security control is specifically designed to establish such a secure perimeter?
- AShared VPC
- BVPC Network Peering
- CVPC Service Controls
- DCloud VPN
Show answer & explanationAnswer & explanation
Correct answer: C. VPC Service Controls
VPC Service Controls create a security perimeter around Google Cloud resources (like BigQuery datasets and Cloud Storage buckets) to restrict data movement and access only from authorized networks and clients. It prevents data exfiltration and ensures that sensitive data remains within the defined perimeter, meeting all the specified requirements.
Why the other options are wrong
- A. Shared VPC allows multiple projects to use a common VPC network, but it doesn't inherently prevent data exfiltration from services or restrict access to a perimeter.
- B. VPC Network Peering connects two VPC networks, but doesn't create a security perimeter around services to prevent exfiltration.
- D. Cloud VPN connects on-premises networks to Google Cloud VPCs but doesn't create a service perimeter or prevent exfiltration from within Google Cloud services.
VPC Service Controls
A Google Cloud security feature that allows you to create a security perimeter around sensitive Google Cloud resources to mitigate data exfiltration risks.
- Restricts operations on supported services to authorized networks.
- Prevents data movement to unauthorized locations.
- Enhances compliance for highly sensitive workloads.
Memory trick: Build a fence around your data, keeping it safe inside.