Ngân hàng đề — Google Cloud Professional Cloud Security Engineer

Tìm thấy 395 câu.

Câu 381
Your organization has recently migrated sensitive customer data to Cloud Storage buckets. For compliance reasons, you must ensure that all vendor data access and administrative access by Google personnel is logged. What should you do?
  1. A Configure Data Access audit logs for Cloud Storage on the project hosting the Cloud Storage buckets.
  2. B Enable Access Transparency for the organization.
  3. C Configure Data Access audit logs for Cloud Storage at the organization level.
  4. D Enable Access Transparency for the project hosting the Cloud Storage buckets.
Xem giải thích

🧩 Phân tích nội dung câu hỏi

Câu hỏi tập trung vào việc bảo mật và tuân thủ trên Google Cloud Platform (GCP), cụ thể là Cloud Storage. Tổ chức của bạn đã di chuyển dữ liệu nhạy cảm của khách hàng vào các bucket Cloud Storage. Để đáp ứng yêu cầu tuân thủ (compliance), bạn cần ghi log (logging) tất cả các hoạt động:

  • Vendor data access: Truy cập dữ liệu bởi các nhà cung cấp bên thứ ba (vendors).
  • Administrative access by Google personnel: Truy cập quản trị bởi nhân viên Google.

📌 Mục tiêu chính: Đảm bảo tính minh bạch và khả năng kiểm toán (audit) cho các truy cập đặc biệt này, không chỉ là truy cập thông thường từ người dùng hoặc service account. Điều này đòi hỏi giải pháp ghi log chuyên biệt cho hành động của Google và vendors, vì audit log thông thường (như Data Access logs) chỉ ghi nhận hoạt động của khách hàng, không phải của Google nội bộ.

🛠️ Bối cảnh GCP mới nhất (cập nhật đến 2026): Theo tài liệu GCP, Access Transparency là tính năng chính thức cung cấp log chi tiết về các truy cập của Google personnel và vendors đến dữ liệu khách hàng, với giao diện xem trực quan. Nó được kích hoạt ở mức organization, không phải project riêng lẻ.

✅ Đáp án đúng và lý do lựa chọn

Đáp án đúng: Enable Access Transparency for the organization.

Lý do:

  • Access Transparency ghi log tất cả các truy cập dữ liệu bởi Google personnel (hỗ trợ, bảo trì, khắc phục sự cố) và vendors (như khi họ hỗ trợ Google truy cập dữ liệu thay mặt).
  • Tính năng này chỉ có thể enable ở mức organization, áp dụng cho toàn bộ tài nguyên con (projects, folders) trong tổ chức, bao gồm Cloud Storage buckets.
  • Log được lưu trữ an toàn, khách hàng có thể xem qua Access Transparency page trong Console, với metadata chi tiết (ai truy cập, lý do, thời gian).
  • Đáp ứng hoàn hảo yêu cầu compliance mà không cần cấu hình phức tạp thêm cho từng project/bucket. ✅ Hoàn hảo cho dữ liệu nhạy cảm!

📋 Giải thích tất cả các phương án (đúng/sai)

Dưới đây là phân tích chi tiết từng lựa chọn, giữ nguyên văn bản gốc bằng tiếng Anh. Tôi sử dụng ✅ cho đúng và ❌ cho sai:

  • ❌ [SAI] Configure Data Access audit logs for Cloud Storage on the project hosting the Cloud Storage buckets.
    Giải thích: Data Access audit logs chỉ ghi nhận truy cập dữ liệu bởi người dùng, service account hoặc ứng dụng của khách hàng (ví dụ: đọc/ghi object trong bucket). Nó không log truy cập từ Google personnel hoặc vendors. Hơn nữa, bật ở mức project chỉ áp dụng cục bộ, không bao quát toàn tổ chức, và có chi phí cao + quota giới hạn (theo Cloud Audit Logs docs 2026). Không đáp ứng yêu cầu vendor/Google access.

  • ✅ [ĐÚNG] Enable Access Transparency for the organization.
    Giải thích: Như đã nêu ở phần đáp án đúng, đây là giải pháp chính xác nhất. Enable ở organization đảm bảo log toàn diện cho tất cả truy cập nhạy cảm từ Google/vendors, áp dụng tự động cho Cloud Storage và các dịch vụ khác. Không cần cấu hình thêm log khác. 🛡️ Tính năng được khuyến nghị cho compliance cao cấp!

  • ❌ [SAI] Configure Data Access audit logs for Cloud Storage at the organization level.
    Giải thích: Tương tự lựa chọn đầu, Data Access logs vẫn chỉ log hoạt động khách hàng, không bao gồm Google personnel hoặc vendors. Dù bật ở organization (có thể từ 2023+ với IAM policies), nó không giải quyết vendor/Google admin access. Sẽ tạo log thừa, tốn kém mà không hiệu quả.

  • ❌ [SAI] Enable Access Transparency for the project hosting the Cloud Storage buckets.
    Giải thích: Access Transparency không hỗ trợ enable ở mức project (chỉ organization/folder từ phiên bản 2024+). Nếu cố gắng, sẽ thất bại vì yêu cầu quyền Organization Admin. Bật ở project không tồn tại, dẫn đến không log được gì cho vendor/Google access. ❌ Sai cấu trúc GCP!

📘 Tài liệu tham khảo (GCP chính thức, cập nhật 2026)

Hy vọng phân tích này giúp bạn ôn thi chứng chỉ hiệu quả! 🚀 Nếu cần thêm ví dụ thực hành, hãy hỏi nhé.

Câu 382
Your organization is implementing a Zero Trust security model and using Chrome Enterprise Premium. The company is interested in governing access to sensitive data stored in Cloud Storage. You need to configure access controls that ensure only authorized users on managed devices can access this data, regardless of their network location. Access should be restricted based on the device's security posture. This requires up-to-date operating system patches and antivirus software. What should you do?
  1. A Grant access to specific users to the VPC Service Controls to create a perimeter to access the Cloud Storage buckets. Configure Identity-Aware Proxy (IAP) to authenticate users before they can access the data.
  2. B Configure IAM conditions based on IP address ranges. Require users to connect through a VPN. Implement endpoint verification software on user devices to check for basic compliance.
  3. C Create an access level in Access Context Manager that requires a device policy. Create a Context-Aware Access policy using this access level. Apply the policy to the VPC Service Controls perimeter that includes the Cloud Storage buckets.
  4. D Use Cloud Firewall rules to restrict access to the Cloud Storage buckets based on the source IP addresses. Require users to authenticate with a multi-factor authentication method.
Xem giải thích

🧩 Phân tích chi tiết nội dung câu hỏi

Câu hỏi tập trung vào việc triển khai mô hình bảo mật Zero Trust trong Google Cloud Platform (GCP), sử dụng Chrome Enterprise Premium. Tổ chức cần kiểm soát truy cập vào dữ liệu nhạy cảm lưu trữ trong Cloud Storage, đảm bảo chỉ người dùng được ủy quyền trên thiết bị được quản lý mới có thể truy cập, bất kể vị trí mạng. Truy cập phải bị hạn chế dựa trên tư thế bảo mật của thiết bị (device posture), cụ thể yêu cầu hệ điều hành có bản vá mới nhất và phần mềm diệt virus.

🔑 Yêu cầu cốt lõi:

  • Không phụ thuộc vào mạng (network-agnostic).
  • Kiểm tra thiết bị: OS patches cập nhật + antivirus.
  • Tích hợp với Chrome Enterprise Premium (hỗ trợ device management trong BeyondCorp Enterprise).
  • Áp dụng cho Cloud Storage buckets.

Đây là kịch bản điển hình của BeyondCorp Enterprise và Context-Aware Access (CAA), nơi kiểm soát truy cập dựa trên ngữ cảnh (context) như user identity + device state, thay vì chỉ IP/VPN. Kiến thức cập nhật đến 2026: GCP tiếp tục mở rộng Access Context Manager (ACM) với device policies hỗ trợ ChromeOS/Endpoint Verification, tích hợp VPC Service Controls (VPC-SC) perimeters (theo tài liệu GCP 2024-2026).

📘 Tài liệu tham khảo:

✅ Đáp án đúng và lý do lựa chọn

Đáp án đúng: Create an access level in Access Context Manager that requires a device policy. Create a Context-Aware Access policy using this access level. Apply the policy to the VPC Service Controls perimeter that includes the Cloud Storage buckets.

Lý do lựa chọn 🛠️:

  • Hoàn hảo phù hợp Zero Trust: Access Context Manager (ACM) tạo access level với device policy kiểm tra chính xác OS patches + antivirus (qua Chrome Enterprise Premium/Endpoint Verification).
  • Context-Aware Access (CAA) policy áp dụng access level này lên VPC Service Controls (VPC-SC) perimeter bao quanh Cloud Storage buckets, chặn dữ liệu exfiltration và chỉ cho phép truy cập từ thiết bị compliant, bất kể network.
  • Không cần VPN/IP, thuần túy context-based. Đây là best practice GCP cho enterprise Zero Trust (cập nhật 2026: hỗ trợ advanced device signals như Chrome browser integrity).

📋 Giải thích tất cả các phương án (đúng/sai)

  • ❌ [SAI] Grant access to specific users to the VPC Service Controls to create a perimeter to access the Cloud Storage buckets. Configure Identity-Aware Proxy (IAP) to authenticate users before they can access the data.
    Phương án này chỉ tập trung vào user identity qua IAP + VPC-SC perimeter, không kiểm tra device posture (OS patches/antivirus). IAP chủ yếu authenticate/mTLS, không enforce device compliance. VPC-SC bảo vệ data access nhưng thiếu context-aware device check, không phù hợp Zero Trust đầy đủ với managed devices.

  • ❌ [SAI] Configure IAM conditions based on IP address ranges. Require users to connect through a VPN. Implement endpoint verification software on user devices to check for basic compliance.
    Dựa vào IP ranges + VPN vi phạm Zero Trust (network perimeter fallacy). IAM conditions IP không linh hoạt với "regardless of network location". Endpoint verification chỉ "basic compliance" nhưng không tích hợp native GCP cho Cloud Storage; thiếu ACM/CAA để enforce device policy toàn diện.

  • ✅ [ĐÚNG] Create an access level in Access Context Manager that requires a device policy. Create a Context-Aware Access policy using this access level. Apply the policy to the VPC Service Controls perimeter that includes the Cloud Storage buckets.
    Như đã giải thích ở trên: ACM device policy ✅ kiểm tra patches/antivirus; CAA policy + VPC-SC perimeter ✅ enforce trên Cloud Storage, hỗ trợ Chrome Enterprise Premium. Best practice cho Zero Trust.

  • ❌ [SAI] Use Cloud Firewall rules to restrict access to the Cloud Storage buckets based on the source IP addresses. Require users to authenticate with a multi-factor authentication method.
    Cloud Firewall (Hierarchical Firewall Policies) chỉ filter network traffic dựa IP, không check device posture. MFA chỉ là user auth, không liên quan device compliance. Không network-agnostic, vi phạm yêu cầu Zero Trust.

Câu 383
Your organization is using AI to improve products through innovation. The developers want to use Gemini in Vertex AI on a project. You need to provide a secure Google Cloud environment to prevent and detect information leakages. What should you do?
  1. A Set up VPC Service Controls perimeters around the Vertex AI project. Enable Data Loss Prevention API for content inspection.
  2. B Grant the developers and AI engineers the Vertex AI User role. Monitor the audit trails with Cloud Logging.
  3. C Deploy Model Armor to protect the Vertex AI endpoint. Review Security Command Center findings to detect information leakages.
  4. D Implement a firewall rule that allows all traffic to and from the Vertex AI API endpoint.
Xem giải thích

🧩 Phân tích chi tiết nội dung câu hỏi

Câu hỏi tập trung vào việc xây dựng môi trường Google Cloud an toàn cho tổ chức sử dụng AI (cụ thể là Gemini trong Vertex AI) trên một dự án. Mục tiêu chính là ngăn chặn (prevent) và phát hiện (detect) rò rỉ thông tin (information leakages).

  • Bối cảnh: Các nhà phát triển muốn sử dụng Gemini (mô hình AI của Google) qua Vertex AI để đổi mới sản phẩm.
  • Yêu cầu bảo mật: Cần giải pháp toàn diện để bảo vệ dữ liệu khỏi bị rò rỉ ra ngoài, đặc biệt trong môi trường AI nơi dữ liệu nhạy cảm có thể bị xử lý hoặc truyền tải.
  • Kiến thức cập nhật (đến 2026): Theo tài liệu Google Cloud mới nhất (Vertex AI phiên bản 2025+), các tính năng như VPC Service Controls và DLP được khuyến nghị mạnh mẽ cho bảo mật data exfiltration trong AI workloads.
    📘 Tài liệu tham khảo:
  • VPC Service Controls
  • Data Loss Prevention (DLP) API
  • Vertex AI Security Best Practices

✅ Đáp án đúng và lý do lựa chọn

Đáp án đúng: Set up VPC Service Controls perimeters around the Vertex AI project. Enable Data Loss Prevention API for content inspection.

Lý do:
🛡️ VPC Service Controls (VPC SC) tạo ra các "perimeter" (ranh giới) xung quanh dự án Vertex AI, ngăn chặn dữ liệu nhạy cảm rời khỏi môi trường được kiểm soát (data exfiltration), bao gồm cả truy cập từ Vertex AI API. Điều này trực tiếp prevent rò rỉ thông tin.
🔍 DLP API được kích hoạt để inspect nội dung (kiểm tra dữ liệu đầu vào/đầu ra), detect và phân loại thông tin nhạy cảm (như PII, secrets) trong thời gian thực, hỗ trợ cả Vertex AI.
Kết hợp hai tính năng này là giải pháp tối ưu và được khuyến nghị chính thức cho môi trường AI trên Google Cloud, đảm bảo cả prevent lẫn detect leakages mà không ảnh hưởng đến workflow phát triển.

📋 Giải thích tất cả các phương án (đúng/sai)

Dưới đây là phân tích từng lựa chọn một cách chi tiết:

  • Set up VPC Service Controls perimeters around the Vertex AI project. Enable Data Loss Prevention API for content inspection.
    ✅ Đúng (như đã giải thích ở trên). Đây là bộ đôi hoàn hảo: VPC SC "khóa chặt" perimeter, DLP "quét sạch" rủi ro nội dung. Phù hợp nhất cho Vertex AI theo best practices 2025+.

  • Grant the developers and AI engineers the Vertex AI User role. Monitor the audit trails with Cloud Logging.
    ❌ Sai. Việc cấp role Vertex AI User chỉ cho phép truy cập cần thiết (least privilege), và Cloud Logging theo dõi audit logs tốt cho monitoring hành vi người dùng. Tuy nhiên, không prevent/detect trực tiếp information leakages – logs chỉ ghi nhận sau sự cố, không chặn dữ liệu rò rỉ ra ngoài (ví dụ: qua API calls không kiểm soát).

  • Deploy Model Armor to protect the Vertex AI endpoint. Review Security Command Center findings to detect information leakages.
    ❌ Sai. Model Armor (tính năng bảo vệ mô hình AI) chỉ bảo vệ endpoint khỏi adversarial attacks (như model poisoning hoặc evasion), không liên quan đến data leakage từ nội dung người dùng. Security Command Center (SCC) phát hiện misconfigurations, nhưng không chuyên detect leakages cụ thể trong Vertex AI – nó là công cụ tổng quát, không thay thế DLP.

  • Implement a firewall rule that allows all traffic to and from the Vertex AI API endpoint.
    ❌ Sai và nguy hiểm. Quy tắc firewall "allow all traffic" mở rộng hoàn toàn truy cập, tạo lỗ hổng lớn cho leakages (data có thể chảy ra ngoài tự do). Đây là anti-pattern bảo mật, trái ngược với nguyên tắc VPC SC và Private Google Access – chỉ nên allow traffic cần thiết qua VPC.

🛡️ Kết luận: Chọn giải pháp đúng giúp tổ chức tuân thủ các tiêu chuẩn như ISO 27001 hoặc SOC 2 trong môi trường AI. Nếu triển khai, hãy test perimeter với dry-run mode của VPC SC trước!

Câu 384
You are responsible for configuring Identity and Access Management in your organization's Google Cloud environment. You need to restrict your organization's users from accessing Cloud Storage buckets in other Google Cloud organizations. What should you do?
  1. A Set a principal access boundary policy with the appropriate enforcement version. Bind the policy to the principals of your organization.
  2. B Configure organization restriction headers for your environment. Only include the organization ID of your organization in the list of allowed resources.
  3. C Create an IAM deny policy on the organization level that prevents access to Cloud Storage buckets outside the organization.
  4. D Enforce domain restricted sharing in your organization. Configure a managed constraint, and only include the principals in your organization.
Xem giải thích

🧩 Phân tích chi tiết nội dung câu hỏi

Câu hỏi tập trung vào việc cấu hình Identity and Access Management (IAM) trong môi trường Google Cloud của tổ chức bạn. Mục tiêu là ngăn chặn người dùng trong tổ chức của bạn truy cập vào các Cloud Storage buckets thuộc các tổ chức Google Cloud khác.

📌 Bối cảnh vấn đề:

  • Trong Google Cloud, các tổ chức (organizations) là đơn vị phân cấp cao nhất, và người dùng có thể được cấp quyền IAM cross-organization nếu không có cơ chế kiểm soát.
  • Yêu cầu cần một giải pháp chính xác, an toàn để giới hạn quyền truy cập chỉ trong tổ chức nội bộ, tránh rủi ro bảo mật như data exfiltration hoặc unauthorized access giữa các tổ chức khác nhau.
  • Giải pháp phải tuân thủ các best practices IAM mới nhất (cập nhật đến 2026), tận dụng các tính năng IAM nâng cao như Principal Access Boundaries (PAB) – một policy loại access boundary được giới thiệu để kiểm soát phạm vi quyền của principal.

✅ Đáp án đúng và lý do lựa chọn

Đáp án đúng: Set a principal access boundary policy with the appropriate enforcement version. Bind the policy to the principals of your organization.

Lý do 🛠️:

  • Principal Access Boundary (PAB) là tính năng IAM chuyên dụng để giới hạn phạm vi tài nguyên mà một principal (người dùng, service account) có thể truy cập, ngay cả khi họ được cấp quyền allow ở nơi khác.
  • Bằng cách set policy với enforcement version phù hợp (ví dụ: version ENFORCED), và bind policy vào principals của tổ chức, bạn đảm bảo principal chỉ truy cập resource trong tổ chức hiện tại (organization ID cụ thể), chặn hoàn toàn access đến Cloud Storage buckets ở tổ chức khác.
  • Đây là giải pháp tối ưu, granular theo khuyến nghị của Google Cloud Security best practices (2024-2026), tránh over-privileging và dễ quản lý ở cấp tổ chức/folder/project.

📋 Giải thích tất cả các phương án (đúng/sai)

  • ✅ Set a principal access boundary policy with the appropriate enforcement version. Bind the policy to the principals of your organization.
    🟢 Đúng: Như đã giải thích ở trên, PAB chính xác giải quyết vấn đề cross-organization access bằng cách enforce boundary trên principals. Enforcement version (như v1beta1 ENFORCED) đảm bảo policy active ngay lập tức.

  • ❌ Configure organization restriction headers for your environment. Only include the organization ID of your organization in the list of allowed resources.
    🔴 Sai: Không tồn tại tính năng "organization restriction headers" trong Google Cloud IAM hoặc Cloud Storage. Đây có thể nhầm lẫn với HTTP headers ở API Gateway hoặc VPC Service Controls, nhưng không áp dụng cho IAM cross-org. Không có "list of allowed resources" kiểu này.

  • ❌ Create an IAM deny policy on the organization level that prevents access to Cloud Storage buckets outside the organization.
    🔴 Sai: IAM deny policy ở cấp organization chỉ áp dụng trong tổ chức đó, không thể chặn access cross-org một cách trực tiếp (vì quyền cross-org được đánh giá ở org đích). Deny policy không granular cho "outside organization" và dễ bị bypass nếu principal có quyền ở org khác.

  • ❌ Enforce domain restricted sharing in your organization. Configure a managed constraint, and only include the principals in your organization.
    🔴 Sai: Domain restricted sharing dùng cho Google Workspace/Drive sharing (giới hạn theo domain email), không liên quan đến Cloud Storage IAM cross-org. Managed constraints (Organization Policy) không hỗ trợ "only principals in organization" cho access boundary; nó dùng cho resource config, không phải principal restriction.

📘 Tài liệu tham khảo (cập nhật mới nhất 2026)

Giải pháp này đảm bảo zero-trust model trong Google Cloud! 🚀 Nếu cần demo code gcloud, hãy cho tôi biết nhé!

Câu 385
Your organization is storing regulated data in Cloud Storage. Data in Cloud Storage buckets is encrypted by Google-managed encryption keys. To meet compliance requirements, you need to update the existing data to use customer-managed encryption keys instead. What should you do?
  1. A Create a new key ring and key in the Cloud Key Management Service. In each Cloud Storage bucket configuration, change the encryption type to customer-managed encryption key.
  2. B Identify which projects contain Cloud Storage buckets with regulated data. Apply the restrictNonCmekServices organization policy constraint to the identified projects or parent folder.
  3. C Create a new key ring and key in the Cloud Key Management Service. Identify which projects contain Cloud Storage buckets with regulated data. Perform a write action on all existing objects in the buckets.
  4. D Create a customer-managed encryption key. Change the encryption type in each Cloud Storage bucket configuration to the newly created key. Perform a write action on all existing objects in the buckets.
Xem giải thích

🧩 Phân tích chi tiết nội dung câu hỏi

Câu hỏi tập trung vào việc cập nhật mã hóa dữ liệu đã tồn tại trong Google Cloud Storage (GCS) để đáp ứng yêu cầu tuân thủ (compliance). Tổ chức đang lưu trữ dữ liệu quy định (regulated data) trong các bucket GCS, hiện được mã hóa bằng Google-managed encryption keys (khóa do Google quản lý, mặc định). Yêu cầu là chuyển sang customer-managed encryption keys (CMEK) – khóa do khách hàng quản lý qua Cloud Key Management Service (KMS).

🔑 Điểm quan trọng:

  • Dữ liệu hiện tại đã được mã hóa bằng khóa Google-managed, nên chỉ thay đổi cấu hình bucket thôi KHÔNG tự động re-encrypt dữ liệu cũ.
  • Để dữ liệu cũ được mã hóa bằng CMEK mới, phải thực hiện write action (ghi lại, như copy hoặc overwrite) trên tất cả objects hiện có.
  • Đây là quy trình chuẩn theo tài liệu Google Cloud (cập nhật đến 2026, không thay đổi lớn từ 2023+).

📘 Tài liệu tham khảo:

✅ Đáp án đúng và lý do lựa chọn

Đáp án đúng: Create a customer-managed encryption key. Change the encryption type in each Cloud Storage bucket configuration to the newly created key. Perform a write action on all existing objects in the buckets.

🛠️ Lý do chi tiết:

  • Tạo CMEK mới qua Cloud KMS (bước 1: chuẩn bị khóa).
  • Cập nhật cấu hình bucket để sử dụng CMEK (uniform bucket-level encryption).
  • Thực hiện write action (ví dụ: gsutil cp -r hoặc Storage Transfer Service) trên tất cả objects cũ để chúng được re-encrypt bằng CMEK mới. Objects mới sẽ tự động dùng CMEK.
  • Quy trình này đảm bảo toàn bộ dữ liệu (cũ + mới) tuân thủ, không để sót dữ liệu cũ vẫn dùng Google-managed keys.

❌ Phân tích tất cả các phương án

Dưới đây là giải thích từng phương án (giữ nguyên văn bản gốc tiếng Anh). Tôi đánh dấu ✅ đúng hoặc ❌ sai, kèm lý do bằng tiếng Việt rõ ràng:

  • [SAI] Create a new key ring and key in the Cloud Key Management Service. In each Cloud Storage bucket configuration, change the encryption type to customer-managed encryption key.
    ❌ Sai vì thiếu bước rewrite dữ liệu cũ: Tạo key ring/key và thay đổi cấu hình bucket chỉ ảnh hưởng objects mới. Dữ liệu cũ vẫn giữ mã hóa Google-managed, không đáp ứng compliance. Cần thêm write action trên objects hiện có.

  • [SAI] Identify which projects contain Cloud Storage buckets with regulated data. Apply the restrictNonCmekServices organization policy constraint to the identified projects or parent folder.
    ❌ Sai vì policy chỉ ngăn tạo mới, không re-encrypt cũ: Policy restrictNonCmekServices cấm tạo resources non-CMEK từ nay về sau (như buckets/objects mới). Nó không chạm đến dữ liệu hiện tại đã mã hóa Google-managed. Không giải quyết vấn đề cốt lõi.

  • [SAI] Create a new key ring and key in the Cloud Key Management Service. Identify which projects contain Cloud Storage buckets with regulated data. Perform a write action on all existing objects in the buckets.
    ❌ Sai vì thiếu cấu hình bucket dùng CMEK: Write action trên objects chỉ re-encrypt nếu bucket đã được set CMEK. Nếu không change bucket config trước, objects mới viết vẫn dùng Google-managed keys mặc định. Bước identify projects thừa nhưng không bù đắp thiếu sót chính.

  • [ĐÚNG] Create a customer-managed encryption key. Change the encryption type in each Cloud Storage bucket configuration to the newly created key. Perform a write action on all existing objects in the buckets.
    ✅ Đúng hoàn toàn: Kết hợp đầy đủ 3 bước cần thiết: tạo key → set bucket config → rewrite objects cũ. Đảm bảo 100% dữ liệu dùng CMEK, phù hợp compliance. Hiệu quả nhất cho quy mô lớn (dùng công cụ như gsutil hoặc Transfer Service).

🧠 Lưu ý thực tế: Với dữ liệu lớn, dùng Storage Transfer Service hoặc gsutil rewrite để tránh downtime. Kiểm tra quota KMS trước khi scale.

Câu 386
There is a vendor who needs access to your company's Google Cloud environment. The vendor uses a third-party identity provider (IdP). You need to integrate this IdP with your company's Google Cloud environment to enable single sign-on (SSO) for the vendor's users in the most secure way. You don't want to manage any of the vendor users' lifecycle management. What should you do?
  1. A Use Google Cloud Directory Sync to synchronize user accounts from the IdP to Google Workspace, and then configure SSO between Google Workspace and Google Cloud.
  2. B Develop a custom application that queries the IdP for user authentication and then programmatically creates Google Cloud user accounts.
  3. C Connect the vendor's IdP with Google Cloud using Workforce Identify Federation.
  4. D Create Google Cloud accounts for each user and synchronize their passwords with the third-party IdP.
Xem giải thích

🧩 Phân tích chi tiết nội dung câu hỏi

Câu hỏi này xoay quanh tình huống bảo mật trong Google Cloud Platform (GCP): Một nhà cung cấp bên thứ ba (vendor) cần truy cập vào môi trường Google Cloud của công ty bạn. Vendor sử dụng một Identity Provider (IdP) bên thứ ba (không phải của Google). Nhiệm vụ là tích hợp IdP này với Google Cloud để kích hoạt Single Sign-On (SSO) cho người dùng của vendor một cách bảo mật nhất, đồng thời không quản lý vòng đời (lifecycle) của các tài khoản người dùng vendor (không tạo, xóa, hoặc đồng bộ tài khoản của họ).

Mục tiêu chính là sử dụng cơ chế federation (liên kết danh tính) để người dùng vendor có thể xác thực qua IdP của họ và nhận quyền truy cập tạm thời vào GCP mà không cần tài khoản Google riêng biệt. Điều này tránh rủi ro bảo mật từ việc lưu trữ mật khẩu hoặc quản lý tài khoản bên trong GCP/Google Workspace. 🛡️

Kiến thức cập nhật đến năm 2026: Theo tài liệu chính thức của Google Cloud (phiên bản mới nhất IAM và Workforce Identity Federation - WIF), đây là best practice cho external workforce federation, hỗ trợ các IdP như Okta, Auth0, Azure AD, v.v., với OIDC/SAML 2.0. 📘

Nguồn tham khảo:

✅ Đáp án đúng và lý do lựa chọn

Đáp án đúng: Connect the vendor's IdP with Google Cloud using Workforce Identity Federation.

Lý do:

  • Workforce Identity Federation (WIF) cho phép liên kết trực tiếp IdP bên ngoài với Google Cloud IAM qua giao thức OIDC hoặc SAML 2.0, cấp external identities (danh tính bên ngoài) để assume IAM roles tạm thời mà không cần tạo tài khoản Google Cloud/Google Workspace.
  • Điều này đảm bảo SSO bảo mật cao (không chia sẻ mật khẩu, sử dụng JWT tokens ngắn hạn), và không quản lý lifecycle (Google không lưu trữ user data, vendor tự quản lý). Hoàn hảo cho vendor access! 🎯
  • Đây là giải pháp recommended bởi Google cho third-party/external users từ năm 2022, với cải tiến bảo mật như attribute-based access control (ABAC) đến 2026.

📋 Giải thích tất cả các phương án (đúng/sai)

Dưới đây là phân tích từng lựa chọn, giữ nguyên văn bản gốc tiếng Anh. Tôi đánh dấu ✅ cho đúng, ❌ cho sai, kèm lý do chi tiết bằng tiếng Việt:

  • [SAI] Use Google Cloud Directory Sync to synchronize user accounts from the IdP to Google Workspace, and then configure SSO between Google Workspace and Google Cloud.
    ❌ Sai vì: Google Cloud Directory Sync (GCDS) chỉ đồng bộ tài khoản từ LDAP/AD sang Google Workspace, tạo ra các user accounts thực tế trong Workspace. Điều này buộc công ty bạn phải quản lý lifecycle (tạo/xóa user khi vendor thay đổi), tăng rủi ro bảo mật (dữ liệu user lưu trong Google), và không phải cách "bảo mật nhất" cho third-party IdP. GCDS không hỗ trợ trực tiếp SSO federation cho GCP IAM. 🗑️

  • [SAI] Develop a custom application that queries the IdP for user authentication and then programmatically creates Google Cloud user accounts.
    ❌ Sai vì: Phát triển app tùy chỉnh để query IdP và tạo user accounts GCP programmatically là giải pháp không scalable, tốn kém, và kém bảo mật (phải tự code lifecycle management, dễ lỗi, lộ khóa API). Vi phạm yêu cầu "không quản lý lifecycle" và không dùng native GCP features. Rủi ro cao với custom code! 🚫

  • [ĐÚNG] Connect the vendor's IdP with Google Cloud using Workforce Identity Federation.
    ✅ Đúng vì: Như đã giải thích ở trên, WIF là giải pháp native, zero-trust của GCP, tích hợp IdP third-party trực tiếp vào IAM pools/providers. Người dùng vendor login qua IdP → nhận short-lived tokens → access GCP resources qua IAM roles. Không tạo accounts, không quản lý lifecycle, bảo mật tối ưu với MFA từ IdP. Best practice! 🏆

  • [SAI] Create Google Cloud accounts for each user and synchronize their passwords with the third-party IdP.
    ❌ Sai vì: Tạo accounts GCP riêng và đồng bộ mật khẩu là cách cũ kỹ, kém bảo mật nhất (chia sẻ mật khẩu hai chiều, dễ bị tấn công brute-force hoặc leak). Buộc quản lý lifecycle đầy đủ (tạo/xóa user), tăng surface attack, và không hỗ trợ true SSO federation. Trái ngược hoàn toàn với zero-trust model hiện đại! 🔒❌

Tóm lại, Workforce Identity Federation là lựa chọn duy nhất đáp ứng tất cả yêu cầu bảo mật và không quản lý user. Nếu triển khai, hãy config IAM workforce pools và map attributes từ IdP! 🚀

Câu 387
Your organization is planning to deploy a large number of Google Kubernetes Engine (GKE) clusters to run business applications in different folders and projects. You must ensure that all GKE nodes always run the latest release to minimize vulnerability risk and administrative effort. What should you do?
  1. A After creating clusters, use the Google Cloud console gcloud container node-pools describe NODE_POOL_NAME --cluster=CLUSTER_NAME command. Examine the upgradeSettings and UpdateInfo output.
  2. B Create a custom organization policy constraint resource.management.autoUpgrade == true with an action type of ALLOW at the organization level before deployment.
  3. C Create a new node pool with the newer version for each cluster. Migrate the workload. Eliminate the outdated node pool.
  4. D Manually run the Google Cloud console gcloud container clusters upgrade CLUSTER_NAME--node-pool=NODE_POOL_NAME --cluster-version VERSION command on newly created clusters regularly.
Xem giải thích

🧩 Phân tích chi tiết nội dung câu hỏi

Câu hỏi tập trung vào việc triển khai một số lượng lớn Google Kubernetes Engine (GKE) clusters trong các folders và projects khác nhau thuộc tổ chức của bạn. Mục tiêu chính là đảm bảo tất cả các node trong GKE luôn chạy phiên bản release mới nhất, nhằm:

  • ✅ Giảm thiểu rủi ro lỗ hổng bảo mật (vulnerability risk) bằng cách vá kịp thời các bản cập nhật bảo mật.
  • ✅ Giảm nỗ lực quản trị (administrative effort) bằng cách tránh các hoạt động thủ công lặp lại.

Vấn đề cốt lõi: Với quy mô lớn (large number of clusters), cần một cơ chế tự động hóa và bắt buộc (enforce) ở cấp tổ chức (organization level) để áp dụng thống nhất cho tất cả clusters mới và hiện tại, mà không phụ thuộc vào cấu hình thủ công từng cluster.

✅ Đáp án đúng và lý do lựa chọn

Đáp án đúng: Create a custom organization policy constraint resource.management.autoUpgrade == true with an action type of ALLOW at the organization level before deployment.

Lý do chi tiết:

  • Đây là cách tối ưu và bắt buộc nhất sử dụng Organization Policy trong Google Cloud để enforce tự động nâng cấp node pools (autoUpgrade: true) cho tất cả GKE clusters trong tổ chức.
  • Policy này với action type ALLOW cho phép chỉ những clusters có autoUpgrade được bật, ngăn chặn việc tạo clusters mà không có tính năng này.
  • Lợi ích: Tự động upgrade nodes đến phiên bản mới nhất tương thích (patch releases và minor versions), giảm rủi ro bảo mật và công sức quản lý. Áp dụng trước deployment để ảnh hưởng đến tất cả projects/folders.
  • Phù hợp với best practice bảo mật GKE (cập nhật đến 2026: GKE Autopilot và Standard clusters đều hỗ trợ auto-upgrade qua Org Policy).

📘 Tài liệu tham khảo:

🛠️ Giải thích tất cả các phương án (đúng/sai)

  • After creating clusters, use the Google Cloud console gcloud container node-pools describe NODE_POOL_NAME --cluster=CLUSTER_NAME command. Examine the upgradeSettings and UpdateInfo output.
    ❌ Sai: Phương án này chỉ dùng để kiểm tra (describe) trạng thái upgrade sau khi tạo cluster, không bắt buộc hoặc tự động áp dụng latest release cho tất cả nodes/clusters. Nó là công cụ giám sát thủ công, không giải quyết quy mô lớn và không giảm administrative effort.

  • Create a custom organization policy constraint resource.management.autoUpgrade == true with an action type of ALLOW at the organization level before deployment.
    ✅ Đúng: Như giải thích ở trên, đây là giải pháp enforce tự động ở cấp tổ chức, đảm bảo tất cả GKE nodes luôn auto-upgrade mà không cần can thiệp thủ công, phù hợp hoàn hảo với yêu cầu minimize risk và effort.

  • Create a new node pool with the newer version for each cluster. Migrate the workload. Eliminate the outdated node pool.
    ❌ Sai: Đây là cách thủ công lặp lại cho từng cluster (rolling upgrade), tốn kém thời gian và effort lớn với "large number of clusters". Không tự động hóa, dễ bỏ sót và tăng rủi ro downtime khi migrate workload.

  • Manually run the Google Cloud console gcloud container clusters upgrade CLUSTER_NAME--node-pool=NODE_POOL_NAME --cluster-version VERSION command on newly created clusters regularly.
    ❌ Sai: Hoàn toàn thủ công và định kỳ (regularly), không khả thi cho quy mô lớn. Dễ quên, tăng administrative effort và rủi ro bảo mật nếu không chạy kịp thời. Không enforce ở cấp tổ chức.

Câu 388
Your company is migrating a three-tier web application to Google Cloud. The application consists of a web frontend, an application backend, and a database. Due to regulatory requirements and existing on-premises infrastructure dependencies, you need to implement a hybrid cloud architecture. The web frontend will be hosted on Google Cloud, while the application backend and the database will remain on-premises initially. You need to ensure secure and efficient communication between the cloud-based frontend and the on-premises backend and database, minimizing latency and maximizing availability. What should you do?
  1. A Establish a Dedicated Interconnect connection between the Google Cloud VPC network and the on-premises network. Configure firewall rules to allow communication between the three tiers.
  2. B Establish a direct internet connection between the Google Cloud VPC network hosting the web frontend and the on-premises network that hosts the backend and database. Configure firewall rules to allow communication between the three tiers.
  3. C Replicate the on-premises backend and database to Google Cloud. Use a hybrid connectivity network endpoint group for the primary. Backup to the zonal network endpoint group.
  4. D Use a highly-available Cloud VPN connection over the public internet to connect the Google Cloud VPC network to the on-premises network.
Xem giải thích

🧩 Phân tích chi tiết nội dung câu hỏi

Câu hỏi mô tả tình huống công ty đang di chuyển ứng dụng web ba tầng (three-tier web application) lên Google Cloud, bao gồm:

  • Tầng web frontend: Được host trên Google Cloud.
  • Tầng application backend và database: Vẫn giữ nguyên on-premises (hạ tầng tại chỗ) do yêu cầu quy định pháp lý (regulatory requirements) và phụ thuộc hạ tầng hiện tại.
  • Yêu cầu chính: Triển khai kiến trúc hybrid cloud để đảm bảo giao tiếp an toàn, hiệu quả giữa frontend trên cloud và backend/database on-premises. Cụ thể cần giảm thiểu độ trễ (minimizing latency) và tối đa hóa tính sẵn sàng (maximizing availability).

🛠️ Vấn đề cốt lõi: Cần giải pháp kết nối hybrid giữa Google Cloud VPC network và on-premises network, ưu tiên kết nối riêng tư, ổn định, băng thông cao, không phụ thuộc internet công cộng để tránh rủi ro bảo mật và độ trễ.

📘 Tài liệu tham khảo:

✅ Đáp án đúng và lý do lựa chọn

Đáp án đúng: Establish a Dedicated Interconnect connection between the Google Cloud VPC network and the on-premises network. Configure firewall rules to allow communication between the three tiers.

Lý do chi tiết:

  • Dedicated Interconnect cung cấp kết nối riêng tư, trực tiếp từ VPC của Google Cloud đến on-premises qua nhà cung cấp dịch vụ (partner hoặc trực tiếp), không qua internet công cộng → Đảm bảo bảo mật cao, độ trễ thấp nhất (dưới 1ms), và băng thông lớn (10-100 Gbps).
  • Kết hợp firewall rules (VPC Firewall Rules và on-premises firewall) để kiểm soát lưu lượng giữa các tầng, tuân thủ nguyên tắc least privilege.
  • Hoàn hảo cho hybrid architecture, hỗ trợ high availability với redundant connections (multi-location).
  • Phù hợp yêu cầu quy định vì dữ liệu không lộ ra public internet.

📋 Giải thích tất cả các phương án (đúng/sai)

  • Establish a Dedicated Interconnect connection between the Google Cloud VPC network and the on-premises network. Configure firewall rules to allow communication between the three tiers.
    ✅ Đúng (như đã giải thích ở trên). Đây là giải pháp tối ưu nhất cho hybrid connectivity với low latency, high throughput, và 99.99% SLA. Không có rủi ro bảo mật từ internet, dễ scale.

  • Establish a direct internet connection between the Google Cloud VPC network hosting the web frontend and the on-premises network that hosts the backend and database. Configure firewall rules to allow communication between the three tiers.
    ❌ Sai. Kết nối trực tiếp qua internet công cộng không an toàn (dễ bị tấn công MITM, DDoS), độ trễ cao (phụ thuộc ISP), và availability thấp (không có SLA). Vi phạm yêu cầu "secure and efficient" và regulatory compliance. Google khuyến cáo tránh cho hybrid production.

  • Replicate the on-premises backend and database to Google Cloud. Use a hybrid connectivity network endpoint group for the primary. Backup to the zonal network endpoint group.
    ❌ Sai. Giải pháp này di chuyển toàn bộ backend/database lên Google Cloud (replicate), không phải hybrid như yêu cầu (backend/database phải remain on-premises). Network Endpoint Group (NEG) dùng cho load balancing, không giải quyết kết nối hybrid mà thay vào đó là full migration – không phù hợp regulatory và dependencies.

  • Use a highly-available Cloud VPN connection over the public internet to connect the Google Cloud VPC network to the on-premises network.
    ❌ Sai. Cloud VPN (HA VPN) mã hóa lưu lượng nhưng vẫn qua public internet → Độ trễ cao hơn Interconnect (IPsec overhead), băng thông giới hạn (thường <10 Gbps), và không minimize latency như yêu cầu. Chỉ phù hợp cho low-bandwidth hoặc temporary; Google ưu tiên VPN cho dev/test, không production hybrid cao tải.

🧠 Kết luận: Dedicated Interconnect là best practice cho hybrid cloud GCP (theo Google Cloud Well-Architected Framework 2026), giúp cân bằng security, performance và compliance! 🚀

Câu 389
Your organization is building an application powered by generative AI that uses sensitive internal data lo train the AI model. The application is built using Vertex AI, which is generally available in your region. You must ensure Google does not use your sensitive data when tuning public models because it could result in your data being shared with other Google Cloud customers. What should you do?
  1. A Do not use Vertex AI for sensitive data. Use only public data with minimal privacy requirements.
  2. B Encrypt your data by using customer-managed encryption keys (CMEK) to have full control over encryption key access.
  3. C Do nothing. Vertex AI foundation models are frozen by default and do not use your data for model-tuning purposes.
  4. D Contact Google support to opt out of model tuning.
Xem giải thích

🧩 Phân tích chi tiết nội dung câu hỏi

Câu hỏi tập trung vào việc xây dựng ứng dụng sử dụng AI sinh tạo (generative AI) trên Vertex AI của Google Cloud, nơi ứng dụng này sử dụng dữ liệu nội bộ nhạy cảm để huấn luyện mô hình AI. Vertex AI đã generally available (GA) ở khu vực của tổ chức. Yêu cầu chính là đảm bảo Google không sử dụng dữ liệu nhạy cảm này để tinh chỉnh (tune) các mô hình công khai (public models), tránh rủi ro dữ liệu bị chia sẻ với khách hàng Google Cloud khác.

📘 Bối cảnh kỹ thuật: Vertex AI là nền tảng quản lý end-to-end cho machine learning/ML trên Google Cloud. Với generative AI, dữ liệu huấn luyện có thể nhạy cảm (như dữ liệu nội bộ doanh nghiệp), và chính sách dữ liệu của Google Cloud cam kết không sử dụng dữ liệu khách hàng để cải thiện mô hình nền tảng (foundation models) mặc định, trừ khi khách hàng chủ động kích hoạt fine-tuning. Điều này phù hợp với Generative AI Supplemental Terms và Vertex AI Data Governance (cập nhật mới nhất đến 2026, không thay đổi chính sách cốt lõi này).

✅ Đáp án đúng và lý do lựa chọn

Đáp án đúng: Do nothing. Vertex AI foundation models are frozen by default and do not use your data for model-tuning purposes.

Lý do chi tiết 🛠️:

  • Các foundation models (như Gemini, PaLM 2) trong Vertex AI được đóng băng (frozen) theo mặc định, nghĩa là Google không sử dụng dữ liệu của bạn để tinh chỉnh hoặc huấn luyện lại mô hình công khai. Dữ liệu chỉ dùng cho inference (suy luận) và custom training nếu bạn chỉ định.
  • Không cần hành động gì thêm vì đây là chính sách mặc định của Vertex AI, tuân thủ Google Cloud Privacy Commitments. Nếu bạn fine-tune, dữ liệu mới cũng không chia sẻ với khách hàng khác.
  • Dẫn nguồn: Vertex AI Generative AI Data Governance & Generative AI on Vertex AI FAQ (cập nhật 2025-2026 xác nhận foundation models frozen by default).

❌ Phân tích tất cả các phương án

Dưới đây là giải thích từng phương án một cách chi tiết, giữ nguyên văn bản gốc tiếng Anh. Tôi đánh dấu ✅ đúng hoặc ❌ sai, kèm lý do bằng tiếng Việt rõ ràng:

  • [SAI] Do not use Vertex AI for sensitive data. Use only public data with minimal privacy requirements.
    ❌ Sai vì: Phương án này quá cực đoan và không cần thiết. Vertex AI hỗ trợ đầy đủ dữ liệu nhạy cảm với các biện pháp bảo mật như VPC-SC, CMEK, và data residency. Cấm sử dụng Vertex AI sẽ làm mất lợi thế của nền tảng GA, trong khi chính sách frozen models đã bảo vệ dữ liệu. Không phù hợp với yêu cầu "must ensure Google does not use your data".

  • [SAI] Encrypt your data by using customer-managed encryption keys (CMEK) to have full control over encryption key access.
    ❌ Sai vì: CMEK (qua Cloud KMS) chỉ kiểm soát mã hóa dữ liệu tại rest/transit, không liên quan đến việc ngăn Google sử dụng dữ liệu cho model tuning. CMEK bảo vệ truy cập dữ liệu nhưng không ảnh hưởng đến chính sách frozen models. Đây là biện pháp bảo mật bổ sung, không giải quyết trực tiếp vấn đề câu hỏi.

  • [ĐÚNG] Do nothing. Vertex AI foundation models are frozen by default and do not use your data for model-tuning purposes.
    ✅ Đúng vì: Như giải thích ở trên, đây là hành động chính xác nhất – không cần làm gì vì foundation models frozen mặc định, đảm bảo dữ liệu không dùng cho tuning public models. Phù hợp 100% với yêu cầu bảo mật dữ liệu nhạy cảm.

  • [SAI] Contact Google support to opt out of model tuning.
    ❌ Sai vì: Không tồn tại tùy chọn "opt out" qua support vì mặc định đã không tune trên dữ liệu khách hàng. Liên hệ support là thừa, có thể dẫn đến hỗ trợ không cần thiết. Chính sách Vertex AI tự động áp dụng frozen state mà không yêu cầu opt-out.

Kết luận tổng quát 🎯: Câu hỏi kiểm tra kiến thức về data governance trong Vertex AI generative AI. Luôn ưu tiên frozen foundation models để bảo vệ dữ liệu nhạy cảm. Để an toàn hơn, kết hợp với Private Google Access và Customer Managed Encryption Keys (dù không bắt buộc ở đây). Tham khảo thêm: Google Cloud Responsible AI Practices (2026 update).

Câu 390
Your organization is deploying a new web application on Compute Engine and needs robust perimeter security. You need to protect the application from common web attacks, including SQL injection and cross-site scripting (XSS), while also controlling network traffic based on the source IP address and user identity. What should you do?
  1. A Implement Cloud Load Balancing and Cloud DNS. Set up Cloud CDN to cache content and mitigate some DDoS attacks. Configure Cloud Armor to provide layer 7 protection.
  2. B Deploy Cloud Armor with its default WAF rules enabled. Configure network firewall rules on the Compute Engine instances to control all traffic based on source IP addresses. Use Cloud IAM to manage which users have roles granting access to the web application.
  3. C Use Google Cloud Armor with pre-configured WAF rules to filter malicious traffic. Implement VPC Service Controls to create a secure perimeter around the application's resources. Manage users with Cloud IAM.
  4. D Deploy Cloud Armor, and configure Cloud Firewall rules to control traffic based on source IP addresses. Integrate with Identity-Aware Proxy to control access based on user identity.
Xem giải thích

🧩 Phân tích chi tiết nội dung câu hỏi

Câu hỏi này tập trung vào việc triển khai bảo mật chu vi (perimeter security) cho một ứng dụng web mới trên Compute Engine trong Google Cloud Platform (GCP). Các yêu cầu cụ thể bao gồm:

  • Bảo vệ khỏi các cuộc tấn công web phổ biến như SQL injection (tiêm mã SQL) và cross-site scripting (XSS) – đây là các mối đe dọa ở Layer 7 (ứng dụng).
  • Kiểm soát lưu lượng mạng dựa trên địa chỉ IP nguồn (source IP address) – liên quan đến Layer 3/4 firewall.
  • Kiểm soát truy cập dựa trên danh tính người dùng (user identity) – cần cơ chế xác thực và ủy quyền ở mức ứng dụng. Mục tiêu là xây dựng lớp bảo vệ toàn diện, kết hợp WAF (Web Application Firewall), firewall mạng, và proxy xác thực. Câu hỏi kiểm tra kiến thức về các dịch vụ GCP như Cloud Armor, Cloud Firewall, và Identity-Aware Proxy (IAP), dựa trên các tính năng cập nhật đến năm 2026 (phiên bản mới nhất: Cloud Armor hỗ trợ adaptive protection và ML-based rules; Cloud Firewall là hierarchical policy-based; IAP tích hợp sâu với BeyondCorp).

📘 Tài liệu tham khảo:

✅ Đáp án đúng: [ĐÚNG] Deploy Cloud Armor, and configure Cloud Firewall rules to control traffic based on source IP addresses. Integrate with Identity-Aware Proxy to control access based on user identity.

Lý do chọn đáp án này 🛡️:

  • Cloud Armor: Cung cấp WAF với ruleset pre-configured (như OWASP Top 10) để chặn SQLi, XSS hiệu quả ở Layer 7, tích hợp với Load Balancer.
  • Cloud Firewall rules: Firewall phân cấp (organization/network level), kiểm soát traffic dựa trên source IP mà không cần rules trên instance (hỗ trợ IP ranges, tags).
  • Identity-Aware Proxy (IAP): Proxy context-aware, kiểm soát truy cập web app dựa trên user identity (Google accounts, OAuth), hỗ trợ BeyondCorp zero-trust. Hoàn hảo cho web app trên Compute Engine. Kết hợp này tạo perimeter security robust, bao quát đầy đủ yêu cầu mà không thừa thãi. ✅ Hoàn chỉnh và tối ưu nhất!

📋 Giải thích chi tiết tất cả các phương án

  • [SAI] Implement Cloud Load Balancing and Cloud DNS. Set up Cloud CDN to cache content and mitigate some DDoS attacks. Configure Cloud Armor to provide layer 7 protection.
    ❌ Sai vì: Không kiểm soát truy cập dựa trên user identity (chỉ có Cloud Armor cho Layer 7 và CDN cho DDoS/caching). Cloud Load Balancing + DNS chỉ là infrastructure cơ bản, thiếu IP-based control và identity proxy. Không đủ robust cho perimeter security đầy đủ.

  • [SAI] Deploy Cloud Armor with its default WAF rules enabled. Configure network firewall rules on the Compute Engine instances to control all traffic based on source IP addresses. Use Cloud IAM to manage which users have roles granting access to the web application.
    ❌ Sai vì:

    • Cloud IAM chỉ quản lý quyền truy cập API/resources (không phải user identity cho web app end-users).
    • "Network firewall rules on Compute Engine instances" ám chỉ VPC firewall rules gắn instance (không phải Cloud Firewall hierarchical), kém scalable và không khuyến nghị cho perimeter.
    • Thiếu tích hợp identity-aware cho web traffic.
  • [SAI] Use Google Cloud Armor with pre-configured WAF rules to filter malicious traffic. Implement VPC Service Controls to create a secure perimeter around the application's resources. Manage users with Cloud IAM.
    ❌ Sai vì:

    • VPC Service Controls (nay là VPC SC Perimeter) dùng chống data exfiltration giữa services (không chặn web attacks như SQLi/XSS hay IP/user control trực tiếp).
    • Cloud IAM lại sai tương tự (không cho web app user access).
    • Cloud Armor đúng phần WAF nhưng các phần còn lại không khớp yêu cầu traffic control.

Kết luận 🎯: Chỉ đáp án đúng mới bao quát WAF + IP firewall + user identity một cách chính xác, tuân thủ best practices GCP Security (zero-trust model). Sử dụng combo này giúp tổ chức đạt compliance cao! 🚀