Soru

Zorluk: OrtaNetwork Security, Firewalls, Cloud Armor, and VPC Service Controls

An enterprise security architect is designing a defense-in-depth network architecture across a multi-project Google Cloud deployment. Match each Google Cloud network security control on the left to its primary architectural use case on the right.

  • VPC Service Controls PerimeterDefine security boundaries around Google Cloud managed services to prevent unauthorized data exfiltration and restricted API access.
  • Cloud Armor Security PolicyMitigate Layer 7 web application vulnerabilities such as SQL Injection and rate-limit unwanted traffic at the external load balancer edge.
  • Hierarchical Firewall Policy with Secure TagsEnforce top-down network traffic rules across all projects within an organization or folder using fine-grained resource tagging.
  • Private Service Connect EndpointConsume producer services or Google APIs privately inside a consumer VPC without establishing transitive VPC peering connectivity.

Cevap

VPC Service Controls Perimeter maps to defining security boundaries to prevent data exfiltration; Cloud Armor Security Policy maps to mitigating Layer 7 web application vulnerabilities at the edge; Hierarchical Firewall Policy with Secure Tags maps to enforcing top-down network rules using resource tagging; Private Service Connect Endpoint maps to consuming services privately without VPC peering.
Each Google Cloud network security tool addresses a distinct operational layer in the defense-in-depth model: VPC Service Controls secures GCP service API boundaries to prevent data exfiltration; Cloud Armor provides edge L7 WAF protection; Hierarchical Firewall Policies enforce centralized organization-wide L3/L4 rules using Secure Tags; and Private Service Connect provides isolated private endpoint access to services without requiring VPC Peering connections.

Adım Adım Çözüm

1
Analyze the role of VPC Service Controls
Identified that VPC Service Controls protect GCP service APIs (e.g., Cloud Storage, BigQuery) from exfiltration, which matches restricting API access across boundaries.
VPC SC acts at the API level rather than traditional IP packet filtering.
2
Analyze the role of Cloud Armor
Identified that Cloud Armor evaluates incoming web traffic at Google's edge, protecting against Layer 7 attacks like SQLi/XSS.
Cloud Armor integrates directly with Cloud Load Balancing for edge security.
3
Analyze Hierarchical Firewall Policies with Secure Tags
Identified that hierarchical policies apply at the organization or folder level and leverage Secure Tags bound to IAM to control instance traffic.
Hierarchical firewalls enforce centralized governance across multiple projects.
4
Analyze Private Service Connect
Identified that Private Service Connect exposes endpoints internally using consumer IP addresses, avoiding VPC Peering requirements.
PSC simplifies private access without IP overlap or transitive peering issues.

Anahtar Kavram

Google Cloud Perimeter Security & Network Controls Selection
Tahmini Süre:1m 30s
Bu soruyu puanla