Google Cloud Digital LeaderSecurity and operations with Google CloudHard
A data analytics company uses Google Cloud for processing sensitive customer data. They need to ensure that their data processing jobs (e.g., using Dataflow or Dataproc) only interact with approved Google Cloud services and prevent any accidental or malicious data movement to unauthorized services or external endpoints. Which Google Cloud service can help establish these secure boundaries around their data processing environment?
- AVPC Service Controls
- BCloud IAM
- CShared VPC
- DCloud Firewall
Show answer & explanationAnswer & explanation
Correct answer: A. VPC Service Controls
VPC Service Controls creates a security perimeter around sensitive resources, including data processing services, preventing data exfiltration to unauthorized services or external endpoints, even if IAM policies are misconfigured.
Why the other options are wrong
- B. Cloud IAM manages 'who can do what' but a misconfigured or compromised IAM policy could still lead to data exfiltration. VPC Service Controls adds an extra layer of defense.
- C. Shared VPC allows multiple projects to share a common network, which is a networking organization tool, not a data exfiltration prevention mechanism.
- D. Cloud Firewall controls network traffic based on IP addresses and ports, but cannot prevent a compromised identity from exfiltrating data to an unauthorized Google Cloud service.
VPC Service Controls
VPC Service Controls creates security perimeters around sensitive Google Cloud resources to prevent data exfiltration and restrict access to authorized networks and identities.
- Mitigates data exfiltration risks for sensitive data.
- Works at the service level, independent of network firewall rules.
- Enforces boundaries even with compromised credentials or misconfigured IAM.
- Supports various Google Cloud services like Dataflow, BigQuery, Cloud Storage.
Memory trick: VPC Service Controls builds an invisible fortress around your data.