Google Cloud Digital LeaderSecurity and operations with Google CloudMedium
A financial services company is implementing a zero-trust security model in their Google Cloud environment. They need to ensure that access to sensitive data in Cloud Storage buckets is restricted based on user identity and context, rather than just network location. Which Google Cloud service is fundamental for defining and enforcing these granular access policies?
- AIdentity and Access Management (IAM)
- BVPC Service Controls
- CCloud VPN
- DCloud Firewall
Show answer & explanationAnswer & explanation
Correct answer: A. Identity and Access Management (IAM)
Identity and Access Management (IAM) is the foundational service for defining granular permissions on Google Cloud resources, allowing access control based on who is accessing, what they are accessing, and under what conditions.
Why the other options are wrong
- B. VPC Service Controls helps create security perimeters to prevent data exfiltration, it complements IAM but IAM defines the core access.
- C. Cloud VPN creates secure connections between networks, not for defining granular access to cloud resources based on identity.
- D. Cloud Firewall controls network traffic flow, not identity-based access to specific resources like Cloud Storage buckets.
Identity and Access Management (IAM)
Google Cloud IAM allows you to manage access control by defining who (identity) has what access (role) to which resource, enabling granular and secure permissions.
- Grants access based on the principle of least privilege.
- Identity: Google Account, Service Account, Google Group, Google Workspace/Cloud Identity domain.
- Role: Collection of permissions (primitive, predefined, custom).
- Resource: Project, folder, organization, or specific service resource.
Memory trick: IAM is the gatekeeper, always verifying claims.