Professional Cloud Security EngineerConfiguring network securityEasy
A security engineer is tasked with preventing data exfiltration from a Google Cloud project containing highly sensitive data. The project hosts several GCE instances, Cloud Storage buckets, and BigQuery datasets. The engineer needs to ensure that these resources can only be accessed from within a defined perimeter and that data cannot be moved to unauthorized projects or external destinations. Which Google Cloud service should be configured to achieve this goal?
- ACloud Load Balancing
- BCloud DNS
- CVPC Service Controls
- DCloud CDN
Show answer & explanationAnswer & explanation
Correct answer: C. VPC Service Controls
VPC Service Controls create security perimeters around sensitive data and resources, preventing data exfiltration and unauthorized access, which directly addresses the scenario's requirements.
Why the other options are wrong
- A. Cloud Load Balancing distributes traffic and provides high availability, not perimeter security for data exfiltration.
- B. Cloud DNS manages domain name resolution and does not provide data exfiltration protection for cloud resources.
- D. Cloud CDN is used for content delivery and caching, not for data exfiltration prevention.
VPC Service Controls
VPC Service Controls help mitigate data exfiltration risks by allowing you to define security perimeters around Google Cloud resources.
- Creates security perimeters
- Protects against data exfiltration
- Works with many Google Cloud services
Memory trick: Perimeter guards sensitive data from all outside threats.