Google Cloud Digital LeaderSecurity and operations with Google CloudHard

A government agency is deploying highly sensitive applications on Google Cloud. They require a mechanism to ensure that data exfiltration is prevented, even if an attacker manages to compromise a virtual machine or a service account within the project. This means restricting data movement to only authorized boundaries. Which Google Cloud service is designed for creating these security perimeters?

  1. ACloud Firewall
  2. BCloud Armor
  3. CIdentity-Aware Proxy (IAP)
  4. DVPC Service Controls
Show answer & explanation

Correct answer: D. VPC Service Controls

VPC Service Controls allows you to define security perimeters around sensitive data and resources to mitigate data exfiltration risks. It restricts access to services from outside the perimeter, even if an attacker has valid credentials.

Why the other options are wrong

  • A. Cloud Firewall controls network traffic between VMs or to/from the internet, but doesn't prevent data exfiltration at the service API level.
  • B. Cloud Armor protects against DDoS and web application attacks, not specifically designed for data exfiltration prevention across services.
  • C. Identity-Aware Proxy (IAP) controls access to applications based on user identity, not for preventing data exfiltration from compromised services.

VPC Service Controls

VPC Service Controls allow you to define security perimeters around Google Cloud resources to prevent data exfiltration, ensuring that data stays within trusted boundaries.

  • Creates security perimeters around sensitive data and services.
  • Mitigates data exfiltration risks.
  • Restricts access to services from outside the perimeter.
  • Works even with compromised identities or misconfigured IAM.

Memory trick: VPC Service Controls builds an unbreachable data fence.

More Security and operations with Google Cloud questions