Soru

Zorluk: KolayNetwork Security, Firewalls, Cloud Armor, and VPC Service Controls

Match each Google Cloud network security requirement with the perimeter control mechanism best suited to fulfill it.

  • Preventing internal users with valid IAM access from copying sensitive BigQuery datasets to unauthorized external Google Cloud projects.VPC Service Controls
  • Protecting public-facing web applications at the external HTTP(S) load balancer against SQL injection attacks and volumetric DDoS.Cloud Armor Security Policies
  • Enforcing organization-wide firewall rules centrally across multiple VPC networks using dynamic resource metadata tags.Hierarchical Firewall Policies with Secure Tags
  • Enabling internal Compute Engine Virtual Machines without public IP addresses to securely reach Google Cloud APIs.Private Google Access

Cevap

VPC Service Controls prevent data exfiltration to unauthorized projects; Cloud Armor Security Policies protect edge applications from DDoS and web application attacks; Hierarchical Firewall Policies with Secure Tags enforce organization-wide traffic control; Private Google Access allows private VMs to communicate with GCP APIs.
Each GCP security feature targets a distinct architectural layer: VPC Service Controls protect against data exfiltration across GCP API boundaries; Cloud Armor provides edge WAF and DDoS defenses at load balancers; Hierarchical Firewall Policies enforce centralized organizational firewall rules with secure tags; and Private Google Access provides secure API egress for private VMs.

Adım Adım Çözüm

1
Analyze the threat of unauthorized data copying by privileged internal users.
Identify that IAM roles alone cannot prevent data movement across project boundaries, requiring VPC Service Controls perimeters.
VPC Service Controls restrict API communication between resources inside and outside a perimeter.
2
Evaluate protection controls for internet-facing web endpoints.
Map Web Application Firewall (WAF) features like SQLi protection and volumetric DDoS defense to Cloud Armor.
Cloud Armor operates at the Google Cloud edge attached to load balancers to block malicious traffic before reaching compute backends.
3
Review enterprise-wide firewall administration requirements.
Select Hierarchical Firewall Policies combined with Secure Tags.
Hierarchical policies apply rules across folder and organization levels that individual VPC admins cannot override.
4
Determine the network service required for private VM outreach to Google services.
Identify Private Google Access.
Private Google Access routes internal VM traffic securely to default Google API endpoints without external IPs.

Anahtar Kavram

Google Cloud Perimeter Security Mechanisms
Bu soruyu puanla