Professional Cloud ArchitectDesign for security and complianceMedium
A public sector agency is migrating its critical applications to Google Cloud. They operate under a zero-trust security model, requiring that all user and service interactions with cloud resources are continuously authenticated, authorized, and encrypted, regardless of network location. They need a service that provides centralized identity management, strong authentication mechanisms (e.g., MFA), and granular authorization across all Google Cloud resources. Which Google Cloud service combination is fundamental to implementing a comprehensive zero-trust security model?
- AIdentity Platform and Cloud CDN
- BCloud Identity and Access Management (IAM)
- CCloud DNS and Cloud Load Balancing
- DCloud Logging and Cloud Monitoring
Show answer & explanationAnswer & explanation
Correct answer: B. Cloud Identity and Access Management (IAM)
Cloud Identity provides centralized user and group management, including strong authentication like MFA. IAM then provides the granular authorization to control what authenticated identities can do with specific Google Cloud resources, forming the cornerstone of a zero-trust model.
Why the other options are wrong
- A. Identity Platform is for customer identity management, and Cloud CDN improves content delivery; neither provides comprehensive zero-trust for internal cloud resources.
- C. Cloud DNS and Cloud Load Balancing are networking services and do not provide identity management or granular authorization for a zero-trust model.
- D. Cloud Logging and Cloud Monitoring are for observability and auditing, which are important for security, but they don't provide the core authentication and authorization mechanisms for zero-trust.
Cloud Identity and IAM for Zero Trust
Cloud Identity provides the 'who' for authentication and user management, while IAM provides the 'what' and 'where' for granular authorization, together forming the foundation for a zero-trust security model in Google Cloud.
- Zero Trust: Never trust, always verify.
- Cloud Identity manages users, groups, and multi-factor authentication.
- IAM controls granular permissions to Google Cloud resources.
Memory trick: Identity + IAM = Invincible Access Management.