Professional Cloud ArchitectDesign for security and complianceMedium

A large public sector agency is migrating its highly sensitive citizen data application to Google Cloud. They operate under a 'Zero Trust' security model, requiring that no user or service is implicitly trusted, even if they are within the organization's network. Access to resources must be continuously verified based on context like identity, device health, and location. Which Google Cloud service combination is most appropriate to implement a Zero Trust model for this application?

  1. ACloud Identity and Access Management (IAM) with Security Command Center
  2. BCloud Armor with reCAPTCHA Enterprise
  3. CVPC Service Controls with Cloud Data Loss Prevention (DLP)
  4. DIdentity-Aware Proxy (IAP) with Access Context Manager
Show answer & explanation

Correct answer: D. Identity-Aware Proxy (IAP) with Access Context Manager

Identity-Aware Proxy (IAP) allows for granular application access control based on identity, and Access Context Manager allows defining fine-grained access policies based on attributes like device health, IP address, and location, which are core tenets of a Zero Trust model.

Why the other options are wrong

  • A. IAM manages permissions but doesn't inherently enforce contextual access or device health checks. Security Command Center is for security posture management and threat detection.
  • B. Cloud Armor provides WAF and DDoS protection, and reCAPTCHA protects against bot traffic. These are external threat prevention tools, not core to internal Zero Trust access for legitimate users and services.
  • C. VPC Service Controls creates perimeters to prevent data exfiltration, and DLP identifies sensitive data. While important for security, they don't primarily address the 'no implicit trust' and 'continuous verification' aspects of Zero Trust for *user access*.

Zero Trust Security Model

A security model where no user, device, or application is implicitly trusted, regardless of their location. Every access request is verified based on identity, context, and policy.

  • Never trust, always verify.
  • Access is granted based on the principle of least privilege.
  • Contextual access control (identity, device, location, time).

Memory trick: IAP and Access Context Manager are the 'Who are you and where are you?' for Zero Trust.

More Design for security and compliance questions