Soru

Zorluk: OrtaNetwork Security, Firewalls, Cloud Armor, and VPC Service Controls

An airline company is modernizing its flight operations architecture on Google Cloud. Match each enterprise perimeter security requirement on the left with the correct Google Cloud security mechanism on the right that fulfills it.

  • Prevent data exfiltration from BigQuery and Cloud Storage to unauthorized external services by enforcing an API boundary.VPC Service Controls
  • Filter incoming HTTP(S) web traffic at the global edge against SQL injection, cross-site scripting, and volumetric rate limits.Google Cloud Armor Security Policy
  • Enforce organization-wide network ingress and egress policies across all existing and future VPC networks, overriding project-level firewall rules.Hierarchical Firewall Policy
  • Connect securely and privately to a third-party partner API published in another VPC without exposing internal IP ranges or establishing VPC peering.Private Service Connect Endpoint

Cevap

The enterprise security requirements match as follows: Data exfiltration prevention for GCP APIs maps to VPC Service Controls; Edge HTTP(S) layer 7 protection maps to Google Cloud Armor Security Policy; Mandatory top-down network rule enforcement maps to Hierarchical Firewall Policy; Private non-transitive partner service access maps to Private Service Connect Endpoint.
Each Google Cloud perimeter security mechanism targets a distinct operational boundary: VPC Service Controls secure API-level communication for managed services; Cloud Armor delivers Layer 7 WAF and rate limiting at the load balancer edge; Hierarchical Firewall Policies enforce immutable organization-wide IP/port filtering; Private Service Connect provides targeted, non-transitive endpoint connectivity between separate VPC environments.

Adım Adım Çözüm

1
Evaluate requirement 1 regarding GCP API exfiltration prevention
Identify that IAM controls user permissions but does not restrict egress destination for API requests. VPC Service Controls create perimeters that restrict data movement outside authorized boundaries.
VPC Service Controls isolate Google-managed platform service resources within defined perimeters.
2
Evaluate requirement 2 regarding edge application protection
Identify that Google Cloud Armor attaches to Global External HTTP(S) Load Balancers to provide Web Application Firewall (WAF) and DDoS protection.
Cloud Armor inspects L7 request attributes at the Google edge prior to hitting backend instances.
3
Evaluate requirement 3 regarding centralized firewall enforcement
Identify that Hierarchical Firewall Policies attach to Organization or Folder nodes to enforce non-overridable network rules across all underlying projects.
Project-level VPC firewall rules can be modified by local project admins, whereas Hierarchical policies enforce top-down compliance.
4
Evaluate requirement 4 regarding isolated service consumption
Identify that Private Service Connect endpoints allow unidirectional connection to consumer services via internal IP mapping without establishing transitive network routing.
VPC Peering exposes full CIDR ranges and does not scale across independent administrative domains as easily as Private Service Connect.

Anahtar Kavram

Designing multi-layered network perimeters using VPC Service Controls, Cloud Armor, Hierarchical Firewalls, and Private Service Connect.
Tahmini Süre:1m 30s
Bu soruyu puanla