Professional Cloud Security EngineerConfiguring access within a cloud solution environmentHard
A company is implementing a security policy that requires all API keys to have HTTP referrer restrictions applied to them. They want to prevent any API key from being used by unauthorized websites or applications. How can this be enforced for all new and existing API keys across all projects in their organization?
- AUse an Organization Policy constraint to enforce HTTP referrer restrictions on API keys.
- BCreate a custom IAM role that includes a condition requiring HTTP referrer restrictions.
- CImplement Cloud Functions to automatically apply HTTP referrer restrictions upon API key creation.
- DManually configure HTTP referrer restrictions on each API key in every project.
Show answer & explanationAnswer & explanation
Correct answer: A. Use an Organization Policy constraint to enforce HTTP referrer restrictions on API keys.
Organization Policies can enforce constraints across an entire organization. The `constraints/apikeys.allowedRestrictions` constraint, specifically for HTTP referrer restrictions, can be used to ensure that all API keys are created or updated with the required security measures, preventing their use from unauthorized origins.
Why the other options are wrong
- B. IAM roles define permissions for principals, not restrictions on the properties of resources like API keys. An IAM condition applies to *when* a role can be used, not *how* a resource (API key) must be configured.
- C. While Cloud Functions could be used, it's a reactive solution that requires custom development and might have a lag. Organization Policies provide a native, proactive, and declarative enforcement mechanism.
- D. Manually configuring each API key is prone to error and not scalable for an organization-wide policy.
Organization Policy for API Keys
Using Google Cloud Organization Policies to enforce specific security constraints on API keys, such as requiring HTTP referrer restrictions.
- Enforces rules across the organization, folders, or projects.
- Uses constraints like `apikeys.allowedRestrictions`.
- Prevents creation or update of non-compliant API keys.
Memory trick: Organization Policies Orchestrate Perfect API Key Protection.