Soru

Zorluk: OrtaNetwork Security, Firewalls, Cloud Armor, and VPC Service Controls

A global logistics company manages dozens of Google Cloud projects across multiple departments within a single organization hierarchy. The security team must enforce mandatory baseline ingress firewall rules—such as blocking port 22 from the public internet—across all current and future projects. The design must prevent project-level administrators from overriding or deleting these baseline security rules, while still allowing central security administrators to delegate fine-grained access control using granular service tags. Which network security architecture should the cloud architect recommend to meet these requirements?

  1. Implement Hierarchical Firewall Policies enforced at the organization or folder level, and utilize Secure Tags to target specific instance workloads.Cevap
  2. B
    Configure VPC Network Peering across all project VPC networks to inherit a centralized set of VPC firewall rules configured in a hub project.
  3. C
    Assign the primitive Owner IAM role to the central security team across all projects so they can manually manage local project VPC firewall rules.
  4. D
    Define VPC Service Controls perimeters around each project to block all inbound network traffic at the IP layer.

Cevap

Implement Hierarchical Firewall Policies enforced at the organization or folder level, and utilize Secure Tags to target specific instance workloads.
Hierarchical Firewall Policies enable organizational security teams to attach immutable firewall rules at the organization or folder node level. Because these rules are evaluated prior to any VPC-level rules, project administrators cannot override them. Integrating Secure Tags allows central teams to securely delegate tag management and apply rules dynamically to specific instance workloads.

Adım Adım Çözüm

1
Analyze the core constraint
Organization-wide mandatory rules are required that cannot be overridden by project admins.
Standard VPC firewall rules are managed at the VPC level and can be altered by project-level network admins.
2
Evaluate GCP organizational security tools
Hierarchical firewall policies sit above VPC firewall rules in the resource hierarchy (Organization and Folder levels).
Rules defined in hierarchical policies are evaluated before local VPC firewall rules and cannot be bypassed by project owners.
3
Evaluate granular targeting capabilities
Secure Tags bound to organization resource hierarchies allow hierarchical policies to selectively apply to tagged virtual machines.
Secure Tags provide fine-grained control and RBAC-governed tag binding for hierarchical policy evaluation.

Anahtar Kavram

Hierarchical Firewall Policies and Secure Tags for organization-wide security governance
Bu soruyu puanla