Memory hook: Authenticate identity; authorize action; audit evidence.
Must remember
Confidentiality limits disclosure, integrity protects correctness, and availability keeps services usable. Authentication establishes identity; authorization decides allowed actions; auditing records evidence. Least privilege grants only necessary access. Zero trust continually evaluates identity/context rather than trusting a network location alone.
Encryption at rest protects stored data, TLS protects transit, and supported confidential-computing environments protect aspects of processing. IAM manages permissions; IAP provides identity-aware access; Cloud Armor protects supported edge workloads; Sensitive Data Protection discovers/de-identifies supported sensitive data. A VPN encrypts a network path, while Interconnect provides dedicated connectivity options with separate encryption design.
Security Command Center helps prioritize cloud posture and threat findings. Google Security Operations supports detection/investigation from telemetry; threat intelligence adds information about adversaries and indicators. Model Armor addresses supported AI input/output threats, but application authorization and validation remain necessary.
Common risks include phishing, ransomware, misconfiguration, credential theft, DDoS and unsafe AI tool use. Provider certifications, transparency and audit reports support assessment; customers still decide lawful use, residency, access and retention. Compliance and security overlap but neither is a complete substitute for the other.
Review details
Distinguish posture (current exposures and weak settings), threat intelligence (adversary/indicator context), and response (containment and recovery actions). Google Threat Intelligence combines Google visibility with Mandiant frontline expertise and VirusTotal intelligence. A finding or IOC match is evidence to assess in context, not automatic proof of a confirmed incident.
Digital sovereignty considers control, applicable obligations and operational dependence as well as where data is stored. Certificate Manager supports certificate management; encryption does not authorize a user. Google's secure-by-design infrastructure and external audit evidence reduce customer assessment work but do not transfer ownership of customer configuration or lawful data use.
Choose under exam pressure
| Requirement | Choice and reason |
|---|---|
| Restrict what a workload can access | Least-privilege IAM. |
| Discover exposed sensitive records | Sensitive Data Protection and appropriate remediation. |
| Investigate cross-system threat activity | Security operations tooling with relevant telemetry. |
Traps
- Encryption cannot compensate for an authorized account being overprivileged.
- A compliant provider does not automatically make an application compliant.
Active recall
1. Authentication versus authorization?
Who you are versus what you may do.
2. What does least privilege reduce?
Unnecessary access and the impact of compromised identities.
3. Why retain audit evidence?
To reconstruct actions and demonstrate controls.
4. What does data residency describe?
Where data is stored/processed under relevant requirements.
5. Why is AI filtering only one layer?
It cannot replace identity, permission checks and safe tool design.