Professional Cloud Security EngineerEnsuring data protectionMedium

A manufacturing company uses Cloud SQL for PostgreSQL to store sensitive intellectual property data. They need to ensure that all connections to the database from their on-premises network are encrypted and authenticated. They also require that the database instance itself is not directly exposed to the public internet. Which configuration should they implement?

  1. AConfigure Cloud SQL with a public IP address and Cloud Armor for IP whitelisting.
  2. BConfigure Cloud SQL with a public IP address and enforce SSL/TLS.
  3. CConfigure Cloud SQL with a private IP address and Cloud VPN/Interconnect, enforcing SSL/TLS.
  4. DConfigure Cloud SQL with a private IP address and Cloud DNS, enforcing SSL/TLS.
Show answer & explanation

Correct answer: C. Configure Cloud SQL with a private IP address and Cloud VPN/Interconnect, enforcing SSL/TLS.

Using a private IP address for Cloud SQL ensures the instance is not exposed to the public internet. Connecting from on-premises via Cloud VPN or Cloud Interconnect establishes a secure, private network path. Enforcing SSL/TLS encrypts and authenticates the traffic over this private connection, meeting all requirements.

Why the other options are wrong

  • A. A public IP address exposes the instance, violating the requirement. Cloud Armor is for protecting public-facing services, not for securing private connections from on-premise.
  • B. A public IP address exposes the instance to the internet, violating the requirement.
  • D. Cloud DNS resolves hostnames but doesn't provide network connectivity or encryption for the connection itself.

Cloud SQL Private IP with Hybrid Connectivity and SSL/TLS

Configuring Cloud SQL with a private IP address, establishing secure private network connectivity from on-premises via Cloud VPN or Cloud Interconnect, and enforcing SSL/TLS for encrypted and authenticated database connections.

  • Private IP removes public internet exposure.
  • Cloud VPN/Interconnect provides secure hybrid connectivity.
  • SSL/TLS encrypts and authenticates client-server traffic.
  • Ensures end-to-end secure communication for sensitive data.

Memory trick: To keep your SQL safe, private IP and VPN/Interconnect are the key, with SSL/TLS for data security!

More Ensuring data protection questions