Professional Cloud Security EngineerEnsuring data protectionMedium

A research institution is using BigQuery to process large datasets that include sensitive health information. They need to create a security perimeter to prevent data exfiltration and ensure that BigQuery datasets can only be accessed from specific projects within their organization. They also want to allow authorized users to query data from outside the perimeter but restrict data egress. Which Google Cloud security service should be used?

  1. ACloud IAM with custom roles and conditions.
  2. BVPC Service Controls with ingress/egress rules.
  3. CCloud Armor with IP-based access policies.
  4. DData Loss Prevention (DLP) with inspection templates.
Show answer & explanation

Correct answer: B. VPC Service Controls with ingress/egress rules.

VPC Service Controls create a security perimeter around sensitive resources like BigQuery datasets, preventing data exfiltration. Ingress and egress rules within the service perimeter can be configured to allow specific access (e.g., from authorized projects or users outside the perimeter) while strictly controlling data movement.

Why the other options are wrong

  • A. IAM controls 'who can do what' but doesn't create network perimeters or prevent data exfiltration at the network level.
  • C. Cloud Armor is a WAF and DDoS protection service for public-facing applications, not for creating perimeters around internal BigQuery datasets.
  • D. DLP inspects and redacts sensitive data but doesn't create network perimeters or prevent data exfiltration from a service perimeter perspective.

VPC Service Controls

A Google Cloud service that allows you to create security perimeters around sensitive data and resources to mitigate data exfiltration risks. It restricts access to and from services within the perimeter, even if IAM policies would otherwise permit it.

  • Creates a network perimeter around Google Cloud services.
  • Prevents data exfiltration by blocking unauthorized data movement.
  • Works with IAM to enforce granular access within the perimeter.
  • Supports ingress/egress rules for controlled access.

Memory trick: VPC Service Controls: Build a 'Vault' around your data, prevent leaks, and control every 'Visitor'!

More Ensuring data protection questions