Professional Cloud ArchitectManage and provision solution infrastructureHard
A security-conscious organization needs to ensure that all virtual machine instances in their Google Cloud projects can only access a specific set of external Google APIs (e.g., Cloud Storage, BigQuery) and are prevented from accessing any other internet resources. They also need to ensure that no data can be exfiltrated to unauthorized external locations. Which security control should be implemented?
- AVPC Network Peering
- BVPC Service Controls
- CPrivate Google Access
- DShared VPC
Show answer & explanationAnswer & explanation
Correct answer: B. VPC Service Controls
VPC Service Controls create security perimeters around Google Cloud resources, restricting data movement and access to only specified APIs and preventing unauthorized access or data exfiltration to external, untrusted networks.
Why the other options are wrong
- A. VPC Network Peering connects two VPCs, but doesn't restrict access to external Google APIs or prevent data exfiltration.
- C. Private Google Access allows VMs without external IP addresses to access Google APIs privately, but it doesn't restrict which APIs can be accessed or prevent data exfiltration to other internet resources.
- D. Shared VPC centralizes network management but doesn't provide fine-grained control over API access or data exfiltration prevention.
VPC Service Controls
A security feature that creates a security perimeter around Google Cloud resources, restricting data movement and access to only authorized APIs and preventing data exfiltration.
- Creates a security perimeter for sensitive data.
- Restricts access to specified Google Cloud APIs.
- Prevents data exfiltration to unauthorized networks.
- Mitigates risks from compromised credentials or rogue insiders.
Memory trick: VPC Service Controls draw a strong line to keep data in its place.