Professional Cloud ArchitectDesign for security and complianceEasy

A financial services company is building a new application on Google Cloud that will process highly sensitive customer transaction data. They need to ensure that this data is isolated from the public internet and that all network traffic between their on-premises data centers and Google Cloud, as well as between services within Google Cloud, is private and secure, without exposing data to the public internet. Which Google Cloud networking service is primarily designed to create a secure, private perimeter for sensitive data and services?

  1. ACloud VPN
  2. BCloud Firewall Rules
  3. CVPC Service Controls
  4. DCloud CDN
Show answer & explanation

Correct answer: C. VPC Service Controls

VPC Service Controls is specifically designed to create a secure perimeter around sensitive data and services, preventing data exfiltration and providing private connectivity. Cloud VPN creates a secure connection to on-premises but doesn't establish a service perimeter. Cloud CDN caches content and is not for security perimeters. Cloud Firewall Rules control traffic flow but do not create a comprehensive perimeter against data exfiltration.

Why the other options are wrong

  • A. Cloud VPN creates a secure IPsec tunnel between your on-premises network and your Google Cloud VPC network but does not establish a service perimeter to prevent data exfiltration between Google Cloud services.
  • B. Cloud Firewall Rules control traffic at the network level (IP, port) but do not prevent data exfiltration by authorized users or services within a project or organization.
  • D. Cloud CDN (Content Delivery Network) is used for content caching and delivery, not for establishing secure perimeters around sensitive data.

VPC Service Controls

A Google Cloud service that allows you to define security perimeters around your sensitive data and services to mitigate data exfiltration risks.

  • Creates a security perimeter around Google Cloud resources.
  • Prevents data exfiltration by restricting data movement.
  • Can be used with private connectivity to on-premises networks.

Memory trick: VPC Perimeters Guard, Data Exfil is Hard.

More Design for security and compliance questions