Your organization is developing a sophisticated machine learning (ML) model to predict customer behavior for targeted marketing campaigns. The BigQuery dataset used for training includes sensitive personal information. You must design the security controls around the AI/ML pipeline. Data privacy must be maintained throughout the model's lifecycle and you must ensure that personal data is not used in the training process Additionally, you must restrict access to the dataset to an authorized subset of people only. What should you do?
Answer : B
The core security and privacy requirement is to prevent personal data from being used in the training process, which necessitates de-identification. Cloud Data Loss Prevention (DLP), also referred to as Sensitive Data Protection (SDP), is the specific Google Cloud tool for this purpose. The secondary requirement, restricting access, is handled by IAM.
Extracts:
'Sensitive Data Protection (SDP)... De-identification enables you to transform your data to reduce data risk while retaining data utility.' (Source 1.4)
'De-identification techniques like encryption, obfuscate raw sensitive identifiers in your data. These techniques let you preserve the utility of your data for joining or analytics, while reducing the risk of handling the data.' (Source 1.1)
'DLP provides tools to classify and de-identify sensitive elements or unwanted content within your data... Find and remove sensitive elements from your data before model training.' (Source 1.4)
IAM policies are the standard mechanism to satisfy the requirement to 'restrict access to the dataset to an authorized subset of people only.' Option B combines the precise technical solution for privacy (DLP De-identification) with the necessary access control (IAM).
A company is running workloads in a dedicated server room. They must only be accessed from within the private company network. You need to connect to these workloads from Compute Engine instances within a Google Cloud Platform project.
Which two approaches can you take to meet the requirements? (Choose two.)
Answer : A, C
To connect Compute Engine instances within a Google Cloud Platform project to workloads running in a dedicated server room that can only be accessed from within the private company network, you can use the following approaches:
Cloud VPN: Cloud VPN securely connects your on-premises network to your Google Cloud Virtual Private Cloud (VPC) network through an IPsec VPN connection. This enables secure communication between your GCP instances and your on-premises workloads over the internet.
Cloud Interconnect: Cloud Interconnect provides direct physical connections between your on-premises network and Google's network. It offers higher bandwidth and lower latency compared to Cloud VPN, making it suitable for workloads that require fast and reliable connectivity.
Both Cloud VPN and Cloud Interconnect allow you to securely connect your on-premises environments to Google Cloud, ensuring that the workloads remain within the private company network.
Reference
Cloud VPN Overview
Cloud Interconnect Overview
You want to evaluate GCP for PCI compliance. You need to identify Google's inherent controls.
Which document should you review to find the information?
Answer : A
To evaluate Google Cloud Platform (GCP) for PCI compliance and identify Google's inherent controls, you should review the 'Google Cloud Platform: Customer Responsibility Matrix'. This document provides detailed information about the shared responsibility model, outlining the security controls managed by Google and those that are the responsibility of the customer.
Steps to access and use the document:
Access the Document:
Go to the Google Cloud compliance resource center.
Locate the 'Customer Responsibility Matrix' for PCI DSS compliance.
Review Inherent Controls:
The document lists various controls and specifies whether they are managed by Google, the customer, or both.
It covers different aspects such as infrastructure security, data protection, and compliance requirements.
Analyze PCI Compliance:
Use the matrix to understand which PCI DSS requirements are inherently addressed by Google Cloud.
Identify the controls you need to implement and manage as a customer to ensure full compliance.
By reviewing this document, you can gain a comprehensive understanding of the inherent controls provided by Google Cloud and the responsibilities you must fulfill to achieve PCI compliance.
Google Cloud Compliance Documentation
PCI DSS Compliance on Google Cloud
A customer has 300 engineers. The company wants to grant different levels of access and efficiently manage IAM permissions between users in the development and production environment projects.
Which two steps should the company take to meet these requirements? (Choose two.)
Answer : B, C
To manage IAM permissions efficiently for a large engineering team with different levels of access in development and production environments, follow these steps:
Create Separate Folders:
Create a folder for the development environment.
Create a folder for the production environment.
This allows you to organize projects and apply different policies and permissions to each environment.
Navigate to IAM & Admin in the GCP Console.
Select 'Folders' from the left-hand menu.
Create a new folder named 'Development'.
Create a new folder named 'Production'.
Create Google Groups:
Create Google Groups for different teams within the engineering department (e.g., Development Team, Production Team).
This helps in managing permissions centrally.
Use the Google Admin Console to create groups.
Add relevant engineers to each group.
Assign Permissions at the Folder Level:
Assign appropriate IAM roles to the Google Groups at the folder level.
For example, grant Viewer role to the Development Team group for the development folder.
Grant Editor or more restrictive roles as required for the Production Team group for the production folder.
Select the development folder.
Go to the 'Permissions' tab.
Click on 'Add' and enter the email address of the Development Team Google Group.
Assign the 'Viewer' role.
Repeat for the production folder, assigning appropriate roles to the Production Team Google Group.
By following these steps, you create a clear separation between development and production environments and manage permissions efficiently using Google Groups and folders.
Google Cloud IAM Documentation
Google Cloud Resource Manager Documentation
Your company is deploying a three-tier web application---web, application, and database---on Google Cloud. You need to configure network isolation between tiers to minimize the attack surface. The web tier needs to be accessible from the public internet, the application tier should only be accessible from the web tier, and the database tier should only be accessible from the application tier. Your solution must follow Google-recommended practices. What should you do?
Answer : C
In Google Cloud, the best practice for micro-segmentation and tier isolation is to use a single VPC with multiple subnets and apply firewall rules using Service Accounts or Network Tags. Using Service Accounts is generally preferred over tags because they are identity-based and more secure.
According to the Google Cloud Security Foundations Guide:
'Segment your VPC networks into subnets to provide logical isolation. Use firewall rules to control traffic between tiers. Instead of relying on IP addresses, use service accounts to define source and destination for firewall rules. This ensures that even if an IP changes, the security policy remains enforced based on the identity of the workload.'
Implementation Details:
Web Tier: Use a firewall rule allowing 0.0.0.0/0 (Internet) to the Service Account associated with the web VMs on port 80/443.
App Tier: Use a firewall rule allowing traffic ONLY from the Web Tier Service Account to the App Tier Service Account.
DB Tier: Use a firewall rule allowing traffic ONLY from the App Tier Service Account to the DB Tier Service Account.
Google Cloud Documentation: 'Best practices for VPC design - Use service accounts to restrict traffic' (https://cloud.google.com/vpc/docs/using-firewalls#service-account-vs-tag).
Professional Cloud Security Engineer Study Guide: Section on 'Configuring Network Security - Micro-segmentation.'
You work for an ecommerce company that stores sensitive customer data across multiple Google Cloud regions. The development team has built a new 3-tier application to process orders and must integrate the application into the production environment. You must design the network architecture to ensure strong security boundaries and isolation for the new application, facilitate secure remote maintenance by authorized third-party vendors, and follow the principle of least privilege. What should you do?
Answer : C
This question combines three security requirements: strong isolation (segmentation), secure remote access, and least privilege.
Strong Isolation: Creating separate VPC networks for each tier (C) provides the strongest network isolation/segmentation, limiting the blast radius compared to a single VPC with subnets (B, D). VPC peering is the standard way to allow controlled communication between these separate VPCs.
Extract: 'Isolate sensitive data in its own VPC network.' (Source 2.5) Segmentation via separate VPCs is a standard best practice for isolating sensitive workloads.
Secure Remote Access and Least Privilege: Identity-Aware Proxy (IAP) is the recommended Google Cloud service to provide secure remote access to virtual machine instances without requiring a public IP or VPN, which aligns with the zero-trust principle of explicit validation and least privilege by verifying user identity and context. Granting SSH keys and root access (A) or the Network Admin role (B) or Project Ownership (D) violates the principle of least privilege.
Extract: 'Access control: Enforce access controls based on user identity and context by using solutions like... Identity-Aware Proxy (IAP). By doing this, you shift security from the network perimeter to individual users and devices. This approach enables granular access control and reduces the attack surface.' (Source 2.2)
Extract: 'BeyondCorp uses Google Cloud tools, such as... and Identity-Aware Proxy, to push the perimeter from the network to individual devices and users.' (Source 2.3)
Extract: 'IAP protects GCP-hosted applications by verifying user identity and context before granting access... When you grant a user access to an application or resource by IAP, they're subject to the fine-grained access controls implemented by the product in use without requiring a VPN.' (Source 2.3)
Option C is the only one that satisfies all three requirements by using separate VPCs (strong isolation) and IAP (secure remote access with least privilege).
Your organization has established a highly sensitive project within a VPC Service Controls perimeter. You need to ensure that only users meeting specific contextual requirements---such as having a company-managed device, a specific location, and a valid user identity---can access resources within this perimeter. You want to evaluate the impact of this change without blocking legitimate access. What should you do?
Answer : D
When implementing new security perimeters or access levels, Google Cloud recommends using Dry Run Mode in VPC Service Controls.12 This allows you to see what would have been blocked without actually disrupting traffic.
According to Google Cloud Documentation (Dry Run Mode for Service Perimeters):
'Dry run mode allows you to test the impact of a service perimeter before enforcing it. You can associate an Access Level (which contains Context-Aware attributes like device status and location) with the dry run configuration. Any request that violates the perimeter or the access level will be logged in Cloud Audit Logs as a 'dry run violation,' but the request will still be allowed to proceed.'13
Evaluation Process:
Define the Access Level in Access Context Manager (Managed Device + Location).
Configure the VPC-SC Perimeter to include the project.
Apply the Access Level to the Dry Run section of the perimeter.
Monitor the VPC Service Controls Violation Dashboard or Audit Logs for dry run errors to identify legitimate users who would be blocked under the new policy.
Google Cloud Documentation: 'Using dry run mode' (https://cloud.google.com/vpc-service-controls/docs/dry-run-mode).