Google Cloud Professional Cloud Security Engineer — Question 166

You work for an ecommerce company that stores sensitive customer data across multiple Google Cloud regions. The development team has built a new 3-tier application to process orders and must integrate the application into the production environment.

You must design the network architecture to ensure strong security boundaries and isolation for the new application, facilitate secure remote maintenance by authorized third-party vendors, and follow the principle of least privilege. What should you do?

Answer options

Correct answer: C

Explanation

Option C is correct as it establishes separate VPC networks for each tier and integrates Identity-Aware Proxy (IAP) to manage access securely, ensuring that only authorized vendors can connect remotely. Option A fails to enforce least privilege by granting root access to vendors, while option B relies on vendor configurations for security, which can be risky. Option D provides too much control to vendors by granting them ownership of the project, compromising security.