Memory hook: IAM answers who; perimeter limits where data may cross.
Must remember
VPC Service Controls establishes boundaries around supported managed services to reduce data exfiltration risk. It complements IAM and VPC firewalls; it is not a general packet firewall. Model ingress/egress rules, access levels and supported services carefully, using dry-run evidence before enforcement to avoid breaking legitimate workflows.
Private Google Access, restricted Google API access and Private Service Connect serve different connectivity needs. Private connectivity does not automatically authorize data access. Cloud NAT supplies outbound address translation without unsolicited inbound connections. Shared VPC centralizes network ownership; peering connects supported VPC paths but does not create transitive connectivity automatically.
Use Cloud Armor for supported edge application protection, Cloud NGFW for supported network enforcement, IAP for identity-aware application/tunnel access, and Secure Web Proxy for governed outbound web access. Certificate Authority Service issues private certificates; Certificate Manager manages supported deployment of certificates. DNS policy and API endpoint restriction are also part of the security path.
Default encryption protects stored data; CMEK gives customer control over supported key use/lifecycle. Cloud HSM provides hardware-backed key operations and Cloud EKM integrates external key management. Revoking a key can stop applications and recovery, so availability and separation of duties matter. Confidential Computing protects supported processing environments; TLS addresses transit. Key rotation does not automatically re-encrypt every historical object with a new version.
Sensitive Data Protection classifies and de-identifies supported data. Secret Manager protects application secrets; KMS protects cryptographic key operations. For AI, restrict training/retrieval datasets, protect prompts/responses, evaluate malicious inputs and enforce authorization on tool actions. Model Armor and other filters are layers, not proof that an agent is safe to execute arbitrary instructions.
Review details
Metadata on a compute instance is not a safe general-purpose secret store. Code running on an instance may be able to obtain the attached identity's tokens; least-privileged attachment, metadata access protection and avoiding injected secrets reduce impact. Cloud Storage lifecycle affects retention/deletion; irreversible locks must be understood before enforcement.
Pseudonymization replaces identifiers and may allow re-identification; tokenization can preserve joinability through controlled mappings; masking changes displayed data; anonymization aims to prevent re-identification. Choose transformation and key/mapping access from the privacy requirement rather than calling every redacted dataset anonymous.
Choose under exam pressure
| Requirement | Choice and reason |
|---|---|
| Reduce exfiltration from supported managed services | VPC Service Controls plus IAM. |
| Keep supported APIs reachable privately | Choose the appropriate Private Google Access/PSC endpoint model. |
| Customer-controlled cryptographic lifecycle | CMEK with deliberately selected software, HSM or external backing. |
Traps
- A service perimeter is not a substitute for IAM.
- Destroying a key may make retained backups permanently unreadable.
Active recall
1. What does VPC Service Controls protect against?
Unauthorized movement of data across configured boundaries for supported services.
2. Does a private route grant access?
No. IAM and service policy still apply.
3. KMS versus Secret Manager?
Cryptographic key management/operations versus storing and retrieving application secret values.
4. Why consider key availability?
Applications and restores can fail when required key operations are unavailable or denied.
5. Why authorize each agent tool action?
A model may be induced to request actions beyond the user’s legitimate permissions.