Professional Cloud Security EngineerEnsuring data protectionMedium
A research institution is processing large datasets in BigQuery that contain sensitive health information. They need to ensure that no sensitive data leaves the Google Cloud environment and that all BigQuery datasets are restricted to a specific Virtual Private Cloud (VPC) network. Which security control should they implement?
- ABigQuery Authorized Views
- BPrivate Google Access
- CVPC Service Controls
- DCloud VPN
Show answer & explanationAnswer & explanation
Correct answer: C. VPC Service Controls
VPC Service Controls create security perimeters around Google Cloud resources (like BigQuery datasets) to prevent data exfiltration. It ensures that data remains within a defined perimeter and can only be accessed from authorized networks, directly addressing the requirement of preventing data from leaving the Google Cloud environment and restricting access to a specific VPC.
Why the other options are wrong
- A. BigQuery Authorized Views control access to specific rows/columns within BigQuery but don't prevent data exfiltration from the service itself to external networks.
- B. Private Google Access allows instances without external IP addresses to access Google APIs, but it doesn't create a security perimeter to prevent data exfiltration.
- D. Cloud VPN connects on-premises networks to Google Cloud VPCs, but it doesn't control data movement between Google Cloud services or prevent exfiltration from within Google Cloud.
VPC Service Controls
A Google Cloud feature that allows you to create security perimeters around sensitive data and services to mitigate data exfiltration risks.
- Protects against data exfiltration.
- Defines authorized network access.
- Enforces security policies across services.
Memory trick: VPC Service Controls: Build a fence, keep data in, no data gets out by chance.