Soru

Zorluk: OrtaNetwork Security, Firewalls, Cloud Armor, and VPC Service Controls

An enterprise organization is designing a security perimeter for its Google Cloud environment. The security architecture must prevent authorized users and service accounts with valid IAM read permissions from exfiltrating sensitive analytics data in Cloud Storage to external locations. Furthermore, the infrastructure team needs to enforce organization-wide firewall guardrails that apply dynamically to instances based on their functional role rather than static IP addresses, across all present and future projects. Which architectural approach fulfills these security requirements?

  1. Enclose the Cloud Storage resources within a VPC Service Controls perimeter, and implement Hierarchical Firewall Policies at the organization level using Secure Tags to dynamically enforce network guardrails.Cevap
  2. B
    Configure IAM Conditions on Cloud Storage buckets to restrict read access to authorized IP ranges, and rely on IAM policies alone to block exfiltration to unauthorized storage buckets.
  3. C
    Connect all spoke VPC networks to a central security VPC using VPC Network Peering, relying on transitive routing through the central hub to inspect and filter all egress storage traffic.
  4. D
    Assign the primitive Owner role to a central security service account, and use legacy network tags on VPC firewall rules to manage egress controls across all projects.

Cevap

Enclose the Cloud Storage resources within a VPC Service Controls perimeter, and implement Hierarchical Firewall Policies at the organization level using Secure Tags to dynamically enforce network guardrails.
The correct solution uses VPC Service Controls to prevent unauthorized data exfiltration from Google Cloud service APIs (such as Cloud Storage) regardless of IAM permissions. Furthermore, Hierarchical Firewall Policies enforced at the organization level combined with Secure Tags allow centralized security teams to dynamically govern network traffic based on workload identity rather than static IP addresses.

Adım Adım Çözüm

1
Evaluate data exfiltration mitigation requirements
Determine that IAM permissions alone do not prevent data exfiltration by authorized entities
VPC Service Controls isolates Google Cloud service API communications within a defined perimeter to prevent copying data to unauthorized external resources.
2
Select organization-wide firewall policy management mechanism
Choose Hierarchical Firewall Policies configured at the Organization or Folder node
Hierarchical policies guarantee consistent security rule enforcement across all child projects without requiring individual VPC firewall maintenance.
3
Identify dynamic target selection method for network rules
Use Secure Tags attached to Compute Engine instances
Secure Tags offer IAM-governed, fine-grained control and apply across project boundaries, unlike legacy network tags which are scoped to a single VPC.

Anahtar Kavram

Perimeter security using VPC Service Controls and organization-wide Hierarchical Firewall Policies with Secure Tags
Bu soruyu puanla