Book Image

Official Google Cloud Certified Professional Cloud Security Engineer Exam Guide

By : Ankush Chowdhary, Prashant Kulkarni
Book Image

Official Google Cloud Certified Professional Cloud Security Engineer Exam Guide

By: Ankush Chowdhary, Prashant Kulkarni

Overview of this book

Google Cloud security offers powerful controls to assist organizations in establishing secure and compliant cloud environments. With this book, you’ll gain in-depth knowledge of the Professional Cloud Security Engineer certification exam objectives, including Google Cloud security best practices, identity and access management (IAM), network security, data security, and security operations. The chapters go beyond the exam essentials, helping you explore advanced topics such as Google Cloud Security Command Center, the BeyondCorp Zero Trust architecture, and container security. With step-by-step explanations, practical examples, and practice exams to help you improve your skills for the exam, you'll be able to efficiently review and apply key concepts of the shared security responsibility model. Finally, you’ll get to grips with securing access, organizing cloud resources, network and data security, and logging and monitoring. By the end of this book, you'll be proficient in designing, developing, and operating security controls on Google Cloud and gain insights into emerging concepts for future exams.
Table of Contents (19 chapters)
16
Google Professional Cloud Security Engineer Exam – Mock Exam I
17
Google Professional Cloud Security Engineer Exam – Mock Exam II
18
Other Books You May Enjoy

Best practices and design considerations

Some of the design considerations are to understand how the resources will be managed inside the project. Using one project might be a good idea to keep it simple, but the isolation and separation of duties will not be achieved. On the flip side, if you use too many projects, there will be a lot of overhead to manage the projects, but you will achieve the separation of duties and the isolation required.

Some of the design considerations to follow when breaking down resources and workloads into projects are as follows. Bear in mind that all considerations are correlated:

  • You don’t want a misconfiguration or a compromise in one operating environment to impact the other. A key consideration is how to reduce the blast radius.
  • Quotas and limits are applied at the project level. It’s undesirable for a dev/test project to consume the quota required by a prod project, or that one app consumes the quota of another.
  • You...