Professional Cloud ArchitectManage and provision solution infrastructureMedium

A healthcare provider is storing patient records in Cloud Storage and needs to ensure that access to these sensitive files is strictly controlled and audited. They require fine-grained access control based on user roles and the ability to track who accessed which file and when. Which combination of Google Cloud security features should they primarily use?

  1. AVPC Service Controls and Shared VPC
  2. BIdentity and Access Management (IAM) and Cloud Audit Logs
  3. CSecurity Command Center and Cloud Security Scanner
  4. DCustomer-Managed Encryption Keys (CMEK) and Data Loss Prevention (DLP)
Show answer & explanation

Correct answer: B. Identity and Access Management (IAM) and Cloud Audit Logs

IAM allows for fine-grained access control to Cloud Storage buckets and objects based on user roles, ensuring only authorized individuals can access patient records. Cloud Audit Logs record administrative activities and data access events, providing the necessary audit trail for compliance and security monitoring.

Why the other options are wrong

  • A. VPC Service Controls protect against data exfiltration, and Shared VPC enables resource sharing, but neither directly provides fine-grained user-role access control or auditing of individual file access.
  • C. Security Command Center is a security posture management service, and Cloud Security Scanner scans for web application vulnerabilities; neither directly controls or audits file access.
  • D. CMEK manages encryption keys, and DLP detects and redacts sensitive data; while important for data protection, they don't provide the primary mechanism for access control based on roles or audit trails of who accessed which file.

IAM and Cloud Audit Logs for Storage Security

IAM defines who can do what with Cloud Storage resources, while Cloud Audit Logs record administrative activities and data access events for auditing and compliance.

  • IAM provides role-based access control (RBAC)
  • Cloud Audit Logs capture 'who did what, where, and when'
  • Essential for compliance and security monitoring

Memory trick: IAM grants the keys, Audit Logs watch the door.

More Manage and provision solution infrastructure questions