Professional Cloud Security EngineerEnsuring data protectionEasy
A company is using Cloud SQL for MySQL and needs to ensure that all network connections to the database instance are encrypted and authenticated, without exposing the database to the public internet. Which configuration should they implement?
- AUse Cloud VPN to connect to the database instance.
- BDisable public IP and enable Private IP with SSL/TLS enforcement.
- CConfigure a firewall rule to allow only specific IP ranges to the public IP.
- DEnable public IP and configure SSL/TLS certificates.
Show answer & explanationAnswer & explanation
Correct answer: B. Disable public IP and enable Private IP with SSL/TLS enforcement.
Disabling public IP ensures the database is not exposed to the public internet. Enabling Private IP allows the database to be accessed only from within a Virtual Private Cloud (VPC) network. Enforcing SSL/TLS ensures that all connections are encrypted and authenticated, meeting all requirements.
Why the other options are wrong
- A. Cloud VPN connects on-premises networks to GCP, but for connections _within_ GCP, Private IP is the native and more direct solution.
- C. Firewall rules on a public IP still expose the database to the internet, even if restricted, and don't inherently enforce encryption or authentication for connections without additional configuration.
- D. Enabling public IP exposes the database to the internet, which contradicts the requirement.
Cloud SQL Private IP with SSL/TLS
Configuring Cloud SQL instances to use an internal Private IP address and enforcing SSL/TLS for all connections, ensuring secure and private network access.
- Database is not exposed to the public internet.
- Connections are encrypted (SSL/TLS).
- Access is restricted to authorized VPC networks.
Memory trick: Private IP is the secret door, SSL is the lock, keeping data safe from any shock.