Professional Cloud ArchitectDesign for security and complianceHard

A financial services company needs to process sensitive customer transaction data using Google Kubernetes Engine (GKE). They are concerned about the possibility of data exfiltration and want to create a secure perimeter around their GKE clusters and associated Google Cloud resources (e.g., Cloud Storage, BigQuery) that prevents data from leaving the defined perimeter, even if credentials are stolen or misconfigurations occur. Which Google Cloud security offering is designed to address this specific concern?

  1. AShared VPC
  2. BVPC Service Controls
  3. CCloud Armor
  4. DPrivate Google Access
Show answer & explanation

Correct answer: B. VPC Service Controls

VPC Service Controls create a security perimeter that isolates sensitive data and resources, preventing data exfiltration by restricting access to authorized APIs and services within the perimeter, even with compromised credentials.

Why the other options are wrong

  • A. Shared VPC allows multiple projects to share a common VPC network but does not prevent data exfiltration across a perimeter.
  • C. Cloud Armor provides DDoS protection and WAF capabilities for internet-facing applications, not an organizational data perimeter.
  • D. Private Google Access allows VMs without external IP addresses to access Google APIs, but it doesn't create a data exfiltration perimeter.

VPC Service Controls

A Google Cloud security feature that allows organizations to create a security perimeter around sensitive data and resources to mitigate data exfiltration risks.

  • Isolates resources like GCS buckets, BigQuery datasets, and GKE clusters.
  • Restricts access to specified APIs and services within the perimeter.
  • Helps prevent data exfiltration and unauthorized access even with compromised credentials.

Memory trick: Perimeters Prevent Data Plunder.

More Design for security and compliance questions