Google Cloud Digital LeaderSecurity and operations with Google CloudMedium
A media company is storing large volumes of sensitive customer data, including personally identifiable information (PII), in Google Cloud Storage buckets. They are concerned about potential data exfiltration by malicious insiders or compromised service accounts. They need to establish a security perimeter to prevent data from leaving their designated project and being accessed by unauthorized services or users outside that perimeter. Which Google Cloud security feature is designed to address this specific concern?
- ACloud Identity and Access Management (IAM)
- BShared VPC
- CData Loss Prevention (DLP) API
- DVPC Service Controls
Show answer & explanationAnswer & explanation
Correct answer: D. VPC Service Controls
VPC Service Controls create security perimeters around Google Cloud resources, such as Cloud Storage buckets, to restrict data movement and access to authorized services within the perimeter, effectively preventing data exfiltration.
Why the other options are wrong
- A. IAM manages who can do what on which resources, but it doesn't create a network perimeter to prevent data from leaving a specific boundary.
- B. Shared VPC allows multiple projects to use a common VPC network, which is a networking feature, not a data exfiltration prevention mechanism.
- C. DLP API helps discover, classify, and redact sensitive data, but it does not prevent data from being exfiltrated across a perimeter.
VPC Service Controls
VPC Service Controls allow you to create security perimeters around Google Cloud resources to mitigate data exfiltration risks.
- Helps prevent data exfiltration by restricting access to authorized services and networks.
- Works by creating service perimeters that define boundaries for resources.
- Can enforce restrictions on API calls between projects and services.
Memory trick: Perimeters Prevent PII from Escaping.