Soru

Zorluk: OrtaNetwork Security, Firewalls, Cloud Armor, and VPC Service Controls

A software enterprise is designing a comprehensive perimeter defense architecture on Google Cloud. Match each enterprise network security requirement with the most appropriate Google Cloud perimeter security mechanism.

  • Prevent authorized internal users and compromised compute resources from exfiltrating sensitive data in BigQuery datasets to unauthorized external Google Cloud projects.VPC Service Controls Service Perimeter
  • Inspect incoming HTTPS traffic at the global load balancer edge to mitigate Layer 7 application attacks, block malicious IP ranges, and enforce rate limiting.Google Cloud Armor Security Policy
  • Enforce mandatory organization-wide baseline ingress firewall rules that apply across all VPC networks and cannot be overridden by project-level administrators.Hierarchical Firewall Policy
  • Allow private on-premises workloads to securely access Google APIs (such as Cloud Storage) over Cloud Interconnect without exposing traffic to the public internet or utilizing public IP addresses.Private Service Connect / Private Google Access

Cevap

1 matches VPC Service Controls Service Perimeter; 2 matches Google Cloud Armor Security Policy; 3 matches Hierarchical Firewall Policy; 4 matches Private Service Connect / Private Google Access.
Each requirement directly aligns with its target GCP perimeter control: VPC Service Controls protect against data exfiltration across API boundaries; Cloud Armor protects public endpoints against Layer 7 and DDoS attacks at the edge; Hierarchical Firewall Policies enforce centralized network rules across the organization hierarchy; and Private Service Connect / Private Google Access enable secure, private routing to Google APIs over hybrid connections.

Adım Adım Çözüm

1
Analyze requirement 1 (Data exfiltration prevention across project boundaries).
IAM roles control who can access resources, but do not prevent authorized users from copying data out to unapproved external projects. VPC Service Controls create a perimeter boundary around services like BigQuery to prevent data exfiltration.
VPC Service Controls restrict API communication between resources inside a perimeter and unauthorized resources outside.
2
Analyze requirement 2 (Edge WAF and Layer 7 protection).
Cloud Armor integrates directly with Cloud Load Balancing to block OWASP Top 10 vulnerabilities, enforce geo-blocking, and rate-limit HTTP(S) traffic.
Cloud Armor is the primary GCP edge security product for application-level threat mitigation.
3
Analyze requirement 3 (Organization-wide non-overridable network security baselines).
Hierarchical Firewall Policies are evaluated before VPC network-level firewall rules and can delegated or locked at the organization/folder level.
Hierarchical firewalls ensure organizational compliance across multi-tenant project structures.
4
Analyze requirement 4 (Private Google API access from on-premises over hybrid connectivity).
Private Service Connect and Private Google Access allow internal networks to access Google managed services using private endpoint IPs over Cloud Interconnect or Cloud VPN.
Private access mechanisms eliminate the need for public IP addresses when accessing GCP storage and database APIs.

Anahtar Kavram

Google Cloud Perimeter Security Architecture and Network Controls
Bu soruyu puanla