Google Cloud Digital LeaderSecurity and operations with Google CloudEasy

A financial services company is implementing a zero-trust security model in their Google Cloud environment. They need to ensure that all access to resources, both by humans and service accounts, is authenticated, authorized, and continuously verified based on context. Which Google Cloud service is fundamental to establishing and enforcing these access controls?

  1. ACloud Storage
  2. BIdentity and Access Management (IAM)
  3. CCloud DNS
  4. DCloud Load Balancing
Show answer & explanation

Correct answer: B. Identity and Access Management (IAM)

Identity and Access Management (IAM) is the foundational service for defining who (identity) can do what (role) on which resources in Google Cloud, which is critical for a zero-trust model.

Why the other options are wrong

  • A. Cloud Storage is an object storage service, not for managing identities and permissions.
  • C. Cloud DNS manages domain name resolution, not access control.
  • D. Cloud Load Balancing distributes traffic, not manages user or service account access.

Identity and Access Management (IAM)

Google Cloud IAM allows you to manage who has what access to which resources. It provides granular control over permissions.

  • Centralized control for managing Google Cloud resource access.
  • Supports users, service accounts, groups, and domains as identities.
  • Uses roles to define permissions, adhering to the principle of least privilege.

Memory trick: IAM is the gatekeeper for every resource.

More Security and operations with Google Cloud questions