Professional Cloud Security EngineerConfiguring access within a cloud solution environmentEasy
A global company uses Google Cloud and needs to restrict certain API keys to only be usable from specific IP address ranges, depending on the region the application is deployed in. For example, API keys used by applications in Europe should only work from European IP ranges. How can this be achieved effectively?
- ACreate a separate API key for each region and manually configure IP restrictions for each.
- BImplement a custom proxy service that filters API requests based on IP address before forwarding them to Google Cloud.
- CConfigure IP address restrictions directly on the API key using the Google Cloud Console or `gcloud` CLI.
- DUse IAM Conditions on API keys to restrict access based on the source IP address.
Show answer & explanationAnswer & explanation
Correct answer: C. Configure IP address restrictions directly on the API key using the Google Cloud Console or `gcloud` CLI.
Google Cloud API Keys support direct configuration of IP address restrictions. You can specify a list of allowed IP addresses or CIDR ranges from which the API key can be used. This is the most straightforward and secure way to enforce source IP restrictions on API keys.
Why the other options are wrong
- A. While this approach would work, it's inefficient and prone to manual error for a global company with many API keys.
- B. Implementing a custom proxy adds unnecessary complexity, latency, and maintenance overhead when the functionality is natively available for API keys.
- D. IAM Conditions apply to IAM policy bindings (who can do what), not directly to API key properties like source IP restrictions. API keys are not IAM principals in the same way service accounts are.
API Key IP Restrictions
A security feature for Google Cloud API keys that limits their usability to requests originating from specified IP addresses or CIDR ranges.
- Configured directly on the API key.
- Enhances security by preventing unauthorized use from other networks.
- Can be combined with HTTP referrer and Android/iOS app restrictions.
Memory trick: Restrict IP, Secure API Key.