Professional Cloud ArchitectDesign for security and complianceMedium

A public sector agency is migrating its highly sensitive citizen data application to Google Cloud. They need to implement a security model where every access request, regardless of its origin (internal or external network, human or machine), is explicitly verified against context-aware policies before granting access. This model must consider device posture, user identity, and resource attributes. Which Google Cloud security framework is designed to achieve this 'never trust, always verify' approach?

  1. AVPC Service Controls with Cloud Firewall Rules
  2. BCloud Armor with reCAPTCHA Enterprise
  3. CZero Trust Security with Identity-Aware Proxy (IAP)
  4. DShared VPC with Private Google Access
Show answer & explanation

Correct answer: C. Zero Trust Security with Identity-Aware Proxy (IAP)

Zero Trust Security is precisely the 'never trust, always verify' model that evaluates every access request based on context (identity, device, location, etc.). Identity-Aware Proxy (IAP) is a key Google Cloud component for implementing Zero Trust by controlling access to applications and resources at the application layer, based on identity and context, rather than network-level firewalls. VPC Service Controls, Shared VPC, and Cloud Armor address other aspects of security like perimeters, networking, and DDoS protection, but not the core 'Zero Trust' principle of verifying every access request.

Why the other options are wrong

  • A. VPC Service Controls establishes security perimeters for services, and Cloud Firewall Rules control network traffic, but these do not inherently implement the identity-centric, context-aware verification of every access request that defines Zero Trust.
  • B. Cloud Armor provides DDoS protection and WAF capabilities, and reCAPTCHA Enterprise protects against bot attacks, but these are perimeter security solutions and do not encompass the comprehensive 'never trust, always verify' approach for all access requests.
  • D. Shared VPC allows resources in different projects to share a common VPC network, and Private Google Access enables private access to Google APIs, neither of which directly implements a Zero Trust security model for application access.

Zero Trust Security

A security model based on the principle of 'never trust, always verify,' requiring strict identity verification for every access request, regardless of whether it originates inside or outside the network perimeter.

  • Verifies every user and device for every access request.
  • Uses context-aware policies (identity, device health, location, etc.).
  • Identity-Aware Proxy (IAP) is a key Google Cloud implementation component.

Memory trick: Verify Every Access, Trust No One's Pass, Context is King, Secure the Glass.

More Design for security and compliance questions