Professional Cloud ArchitectManage and provision solution infrastructureHard
A security-conscious organization needs to ensure that all their Google Cloud resources (Compute Engine, Cloud Storage, BigQuery) are protected from data exfiltration and unauthorized access, especially when accessed from external networks. They want to create a security perimeter that restricts data access to only authorized services and IP ranges, even if an attacker compromises credentials. Which Google Cloud security control should they implement?
- AShielded VMs
- BVPC Flow Logs
- CVPC Service Controls
- DCloud IAM with Organization Policy Service
Show answer & explanationAnswer & explanation
Correct answer: C. VPC Service Controls
VPC Service Controls create security perimeters around sensitive data and resources, restricting access to authorized services and IP ranges. This prevents data exfiltration by ensuring that data cannot leave the perimeter, even with compromised credentials, and is a robust defense against unauthorized access from external networks.
Why the other options are wrong
- A. Shielded VMs provide enhanced security for individual VM instances (e.g., secure boot), but do not create a network perimeter for data exfiltration protection across multiple services.
- B. VPC Flow Logs record network traffic, which is useful for auditing and analysis, but does not actively prevent data exfiltration or unauthorized access.
- D. Cloud IAM and Organization Policy Service control who can do what with resources, but do not create a network perimeter to prevent data exfiltration from authorized users with compromised credentials.
VPC Service Controls
A Google Cloud security feature that allows you to define security perimeters around your sensitive data and resources, mitigating data exfiltration risks.
- Creates network perimeters to isolate services.
- Prevents data exfiltration even with compromised credentials.
- Restricts access to authorized networks and identities.
Memory trick: VPC Service Controls perimeter protects data from leaving.