Professional Cloud Security EngineerEnsuring data protectionHard

A large enterprise wants to prevent data exfiltration from their Google Cloud environment. They have identified that sensitive data in Cloud Storage buckets should never be accessible from the public internet, even if accidentally misconfigured. They also need to ensure that API calls from their on-premises network to these buckets are allowed. Which two actions should they take?

  1. ASet Object ACLs to private and configure a BigQuery Authorized View.
  2. BUse `storage.admin` role for all access and enable bucket versioning.
  3. CEnable uniform bucket-level access on the buckets and configure a VPC Service Controls perimeter.
  4. DDisable public access prevention on the buckets and use Cloud VPN for on-premises access.
Show answer & explanation

Correct answer: C. Enable uniform bucket-level access on the buckets and configure a VPC Service Controls perimeter.

Uniform bucket-level access ensures that all objects in a bucket inherit IAM policies from the bucket, effectively preventing object ACLs from making data publicly accessible. A VPC Service Controls perimeter further prevents data exfiltration by creating a security boundary around Cloud Storage, and it allows defining ingress rules to permit API calls from trusted on-premises networks.

Why the other options are wrong

  • A. Object ACLs are superseded by uniform bucket-level access. BigQuery Authorized Views are for BigQuery, not Cloud Storage data exfiltration prevention.
  • B. `storage.admin` grants excessive permissions and versioning helps with recovery, not exfiltration prevention or strict access control.
  • D. Disabling public access prevention would increase the risk of public exposure, contradicting the goal. Cloud VPN is for connectivity, not directly a perimeter for exfiltration.

VPC Service Controls & Uniform Bucket-Level Access for Cloud Storage

A combination of security controls to prevent data exfiltration from Cloud Storage buckets and enforce consistent access policies.

  • Uniform bucket-level access simplifies and centralizes permissions.
  • VPC Service Controls creates a security perimeter around services.
  • Together, they prevent public access and data exfiltration.

Memory trick: Uniform access for the bucket, VPC Service Controls builds the gate, no data escapes, it's too late!

More Ensuring data protection questions