Professional Cloud ArchitectDesign for security and complianceHard

A defense contractor is migrating sensitive military project data to Google Cloud. They require strict network isolation for their virtual machines (VMs) and other resources, ensuring that no traffic can flow between different projects or even different departments within the same project without explicit, granular control. The network design must prevent accidental exposure and limit the blast radius of any security incidents. Which Google Cloud networking construct is best suited to provide this level of isolation and granular control?

  1. AA single large VPC network spanning all projects, managed by a central firewall
  2. BVPC Service Controls per project to isolate resources
  3. CShared VPC with separate Service Projects and granular firewall rules
  4. DMultiple separate VPC networks, each in its own project and peered together
Show answer & explanation

Correct answer: D. Multiple separate VPC networks, each in its own project and peered together

For the highest level of isolation and to prevent accidental cross-project or cross-department traffic, multiple separate VPC networks, each in its own project, is the most robust approach. Peering these networks provides controlled communication channels. Shared VPC centralizes networking but can introduce blast radius risks if not meticulously managed. A single large VPC is antithetical to isolation. VPC Service Controls isolates services, but the question focuses on network isolation between VMs and resources directly.

Why the other options are wrong

  • A. A single large VPC network directly contradicts the requirement for strict network isolation between different projects and departments, as all resources within it share the same network space.
  • B. VPC Service Controls creates perimeters around services to prevent data exfiltration and control API access, but it does not primarily provide granular network isolation between VMs and resources within different VPC networks or projects at the IP level.
  • C. Shared VPC allows central network management but can increase the blast radius if not carefully controlled, and its primary goal is not maximal isolation between distinct projects/departments but rather shared infrastructure.

VPC Network Isolation Strategies

Methods to logically separate and control network traffic between resources in Google Cloud, ranging from shared to highly isolated.

  • Separate VPCs offer maximum isolation.
  • Shared VPC centralizes networking but requires careful management.
  • Peering allows controlled communication between isolated VPCs.

Memory trick: Separate VPCs, Walls are High, Blast Radius Low, Secure the Sky.

More Design for security and compliance questions