An enterprise security team must ensure that authorized users inside an organization cannot exfiltrate sensitive data from Google Cloud Storage buckets into external, unauthorized projects. Which Google Cloud feature should the architecture team implement to establish a security perimeter around these managed service resources?
- VPC Service ControlsAnswer
- BIdentity and Access Management (IAM) permissions alone
- CVPC Network Peering
- DPrimitive IAM Roles at the Organization Level
Answer
VPC Service Controls
VPC Service Controls enable organizations to construct a perimeter around managed Google Cloud services such as Cloud Storage. This prevents data exfiltration by restricting API calls to authorized services and projects inside the perimeter.
Step-by-Step Solution
Key Concept
VPC Service Controls Service Perimeters