Soru

Zorluk: ZorNetwork Security, Firewalls, Cloud Armor, and VPC Service Controls

A financial enterprise is designing a perimeter security architecture on Google Cloud for a payment processing platform deployed across multiple projects. The architectural requirements specify that workload instances must privately access Google APIs (such as Cloud Storage and BigQuery) without internet egress, while strictly preventing data exfiltration to external GCP organizations. Additionally, network administrators require centralized, non-bypassable firewall rules across all projects, and the design must adhere to GCP constraints prohibiting transitive routing across peered VPCs. Which TWO design choices should the Cloud Architect implement to satisfy these security and network requirements?

  1. Configure a VPC Service Controls perimeter encompassing the payment processing projects and route access to Google APIs via Private Service Connect (PSC) endpoints.Cevap
  2. Apply Hierarchical Firewall Policies at the Organization node and utilize Secure Tags to enforce consistent security rules across project VPCs.Cevap
  3. C
    Establish VPC Network Peering between a central management hub VPC and all workload spoke VPCs, configuring the hub VPC to route administration traffic transitively between spokes.
  4. D
    Rely exclusively on fine-grained Cloud IAM roles for storage access while deploying Cloud NAT to direct outbound workload traffic to default Google API endpoints.

Cevap

The architect must configure a VPC Service Controls perimeter combined with Private Service Connect endpoints for API security and exfiltration prevention, and deploy Hierarchical Firewall Policies with Secure Tags to enforce centralized organization-wide network firewall rules.
Implementing VPC Service Controls with Private Service Connect ensures that Google API requests remain within a strictly defined security boundary, effectively mitigating data exfiltration risks. In addition, Hierarchical Firewall Policies paired with Secure Tags enable organization-wide network governance and mandate uniform security policy enforcement that cannot be altered at the project level.

Adım Adım Çözüm

1
Evaluate data exfiltration prevention and API access requirements.
Identified that VPC Service Controls combined with Private Service Connect endpoints fulfills private access while blocking boundary cross-organization exfiltration.
IAM roles enforce access control but do not prevent authorized entities from transferring data outside perimeter boundaries.
2
Evaluate centralized rule enforcement and network governance.
Selected Hierarchical Firewall Policies attached at the organization level with Secure Tags.
Hierarchical policies cannot be overridden by project-level firewall rules and provide consistent security posture.
3
Analyze network topology constraints.
Rejected transitive hub-and-spoke VPC Peering design.
VPC Network Peering does not support transitive routing in Google Cloud.

Anahtar Kavram

Designing multi-project GCP perimeter security using VPC Service Controls, Private Service Connect, and Hierarchical Firewall Policies.
Bu soruyu puanla