Professional Cloud Security EngineerConfiguring network securityMedium
A security engineer is investigating a potential data exfiltration attempt from a Google Cloud project. They suspect that an attacker might be trying to move data from a Cloud Storage bucket to an external, unauthorized location. The project is already part of a VPC Service Controls perimeter. How can the engineer quickly determine if the suspected exfiltration attempt was blocked by the perimeter?
- AUse Network Intelligence Center's Connectivity Tests to simulate traffic to the external location.
- BExamine the VPC Service Controls audit logs (specifically 'ACCESS_DENIED' events) for the perimeter.
- CCheck Cloud Audit Logs for 'data access' events related to Cloud Storage.
- DReview VPC Flow Logs for traffic from the project to external IP addresses.
Show answer & explanationAnswer & explanation
Correct answer: B. Examine the VPC Service Controls audit logs (specifically 'ACCESS_DENIED' events) for the perimeter.
VPC Service Controls generates specific audit logs for violations, including 'ACCESS_DENIED' events when a request violates a perimeter policy. These logs are the most direct way to confirm if an exfiltration attempt was blocked by the perimeter.
Why the other options are wrong
- A. Connectivity Tests simulate reachability but don't log actual blocked requests by a VPC Service Controls perimeter.
- C. Cloud Audit Logs record operations but might not explicitly state 'blocked by perimeter' unless the service itself logs it, which is less direct than PSC audit logs.
- D. VPC Flow Logs show network traffic but don't indicate if a service control perimeter blocked a service-level operation.
VPC Service Controls Audit Logs
VPC Service Controls generates audit logs that record policy violations, including 'ACCESS_DENIED' events when a request attempts to cross a perimeter boundary unlawfully.
- Logs 'ACCESS_DENIED' events for perimeter violations.
- Provides details about the violating request and its context.
- Crucial for monitoring and troubleshooting VPC Service Controls deployments.
Memory trick: Perimeter logs are the security guard's report.