---
tags:
- cloud
- l1
- flashcard-deck
- gcp-security
---
<!-- wiki:breadcrumb:start -->
[Portal](../../../../library/portal/index.md) | **Level:** [L1: Foundations](../../../../library/portal/levels.md) | **Topics:** [GCP Troubleshooting](../../../../library/portal/topics.md) | **Domain:** Cloud
<!-- wiki:breadcrumb:end -->

id	category	difficulty	tags	question	answer	source_path
gcp-security/0a04e9a5656f	gcp-security	medium	gcp,networking,iam,security	What are usecases of IAP ?	Identity-Aware Proxy (IAP) is a GCP service that provides centralized access management for GCP resources. Use cases for IAP include:\nSecure Remote Access: Allows employees or users to securely access resources from anywhere without a VPN.\nWeb Application Protection: Protects web applications from unauthorized access.\nGranular Access Control: Enables fine-grained access control based on user identity rather than network location.	projects/knowledge/interview/gcp/068-what-are-usecases-of-iap.txt
gcp-security/1c44c006ad5e	gcp-security	hard	gcp,iam,compute	Explain Resource Manager in GCP.	GCP Resource Manager is a hierarchical organization tool for managing and governing resources. It allows organizations to organize and manage their GCP resources, projects, and services, offering centralized control over resource allocation, permissions, and organization policies. It provides a clear view of resource usage and access control, enabling consistent and efficient management across an organization's GCP projects.	projects/knowledge/interview/gcp/134-explain-resource-manager-in-gcp.txt
gcp-security/26a37cd2f6f2	gcp-security	hard	gcp,iam,compute	Describe Identity and Access Management (IAM) in GCP.	IAM manages access control for GCP resources, allowing setting granular permissions for users and services.\nKey Aspects:\n* Principle of Least Privilege: Grants only necessary permissions to entities based on their roles.\n* Resource Hierarchy: Manages permissions across organizations, folders, and projects.	projects/knowledge/interview/gcp/095-describe-identity-and-access-management-iam-in-gcp.txt
gcp-security/2b6e306a7930	gcp-security	medium	gcp,security,database	Explain Google Cloud SQL.	It's a fully managed relational database service supporting MySQL, PostgreSQL, and SQL Server. Provides automated backups, replication, and patches. Ideal for applications needing relational databases without the hassle of managing them.	projects/knowledge/interview/gcp/093-explain-google-cloud-sql.txt
gcp-security/388f86bb4638	gcp-security	hard	gcp,security	How does Google Cloud Key Management Service (KMS) work?	KMS is a cryptographic key management service allowing the creation, storage, and management of cryptographic keys for use by other GCP services.\n* Key Creation and Management: KMS enables the generation, rotation, and destruction of encryption keys. Customers have control over these keys and can manage their lifecycle.	projects/knowledge/interview/gcp/119-how-does-google-cloud-key-management-service-kms-w.txt
gcp-security/443d17c53a71	gcp-security	hard	gcp,iam,security	How does GCP handle data governance and compliance requirements?	GCP provides a range of compliance certifications and features for meeting data governance requirements. It provides tools and controls for data classification, access controls, encryption, and auditing to meet industry-specific compliance standards. GCP services such as Cloud IAM, Data Loss Prevention (DLP), and security tools assist in ensuring compliance with regulations and organizational policies.	projects/knowledge/interview/gcp/133-how-does-gcp-handle-data-governance-and-compliance.txt
gcp-security/4d740562b6c6	gcp-security	hard	gcp,compute	How does GCP handle compliance with various regulations?	GCP maintains a robust compliance program, aligning with global standards and regulations, ensuring that the platform meets strict standards set by different industries and regions. GCP maintains a wide array of certifications, including SOC 1, 2, and 3, ISO 27001, PCI DSS, HIPAA, and GDPR compliance. Here's how GCP handles compliance:	projects/knowledge/interview/gcp/111-how-does-gcp-handle-compliance-with-various-regula.txt
gcp-security/5c27e3044910	gcp-security	medium	gcp,iam	Explain roles and permissions	"Role is an encapsulation of set of permissions. For example an ""owner"" role has more than 3000 assigned permissions to the different components and services of GCP."\n\nRemember: Three role types: Basic (Owner/Editor/Viewer — broad), Predefined (service-specific), Custom (user-defined).\n\nGotcha: Basic roles are too broad for production. Use predefined or custom roles for least privilege.\n\nNumber anchor: Owner role has 3000+ permissions. Viewer has ~300. Use the IAM recommender to right-size.	projects/knowledge/interview/gcp/010-explain-roles-and-permissions.txt
gcp-security/69fa774f7e1a	gcp-security	medium	gcp,security,compute	What are os policies ? or How can you perform automatic patch management in GCP ? or How do you ensure a certain package in installed on all incoming VMs?	OS Policies in GCP enable administrators to define and enforce policies on operating systems across VM instances. This includes automatically managing OS patches, updating packages, and enforcing configurations to ensure consistency and security compliance across the infrastructure. Through OS policies, administrators can define rules for automatic patch management, ensuring that specific packages are installed or updated on all incoming VMs as they are provisioned.	projects/knowledge/interview/gcp/053-what-are-os-policies-or-how-can-you-perform-automa.txt
gcp-security/6aad6f4636f5	gcp-security	medium	gcp,networking,iam,security	What is Cloud Identity-Aware Proxy (IAP)?	IAP is a service that controls access to web applications running on GCP. It allows access to applications based on a user's identity and context, rather than the traditional method of using a VPN.\nIAP offers:\n* Context-Aware Access: It considers user identity and context, such as device security status and geographic location, to grant access.	projects/knowledge/interview/gcp/102-what-is-cloud-identity-aware-proxy-iap.txt
gcp-security/6af69bce77e0	gcp-security	medium	gcp,security	What is Customer-Supplied Encryption Key (CSEK)?	It's a feature allowing customers to manage their encryption keys used for data at rest in GCP services.\nKey Points:\n* Customer Control: Customers generate and manage their encryption keys outside of GCP.\n* Data Encryption: Customers can use these keys to encrypt their data before storing it in GCP services.\nUse Case:\nCSEK enables customers to maintain control over their data encryption keys, ensuring an additional layer of security and compliance for sensitive data stored in GCP.	projects/knowledge/interview/gcp/096-what-is-customer-supplied-encryption-key-csek.txt
gcp-security/6da755c2d75c	gcp-security	hard	gcp,security	What do you understand by Chronicle ?	Chronicle is Google's cybersecurity intelligence platform that leverages massive data analysis and machine learning to detect and mitigate cybersecurity threats. It is designed to handle large-scale data with the use of Google's infrastructure, enabling security analysts to detect and understand threats. Chronicle helps in identifying security incidents across an organization's entire digital infrastructure and provides a comprehensive view of threats.	projects/knowledge/interview/gcp/067-what-do-you-understand-by-chronicle.txt
gcp-security/7166043e97e5	gcp-security	medium	gcp,networking,security	Describe Google Cloud Armor.	Cloud Armor is a DDoS and application defense service providing security against web-based threats. It offers customizable defenses to secure internet-facing applications. Key features include:\n* DDoS Protection: Defends against volumetric and protocol-based DDoS attacks.	projects/knowledge/interview/gcp/120-describe-google-cloud-armor.txt
gcp-security/7b80a64db3bf	gcp-security	medium	gcp,compute,security	What are sole-tenant-nodes ?	Sole-Tenant Nodes are physical Compute Engine servers dedicated to a single user or organization. They offer the advantage of complete control over instance placement on the host hardware. This is beneficial for workloads that require specific hardware configurations, security, or compliance requirements that necessitate dedicated resources.	projects/knowledge/interview/gcp/051-what-are-sole-tenant-nodes.txt
gcp-security/7ff9cf9845db	gcp-security	medium	gcp, control-flow	Describe GCP's approach to GDPR compliance.	GCP offers features to assist customers in their GDPR compliance efforts by providing tools for data protection and control. GCP has designed its services to help customers comply with GDPR. Here's how GCP approaches GDPR compliance:	projects/knowledge/interview/gcp/112-describe-gcps-approach-to-gdpr-compliance.txt
gcp-security/8bc2f5c6b40b	gcp-security	medium	gcp,iam	What are service accounts in GCP?	Service accounts represent non-human users and are used to authenticate and authorize calls to GCP APIs. They act as non-human users and are designed to authenticate the code running in these environments. Service accounts can be assigned specific roles and permissions to access GCP resources securely, allowing fine-grained control over what services can do within the GCP ecosystem.	projects/knowledge/interview/gcp/135-what-are-service-accounts-in-gcp.txt
gcp-security/9581b2eef529	gcp-security	easy	gcp,iam	What is Identity Platform ?	Google Cloud Identity Platform is an authentication service that allows developers to easily integrate authentication and identity services into their applications. It supports multiple identity providers, enabling user authentication and management.	projects/knowledge/interview/gcp/081-what-is-identity-platform.txt
gcp-security/9a30a2f1f757	gcp-security	medium	gcp,security,compute	What is VMware Enginer offering of GCP ?	The VMware Engine is a fully managed VMware environment on GCP that allows enterprises to migrate and run their VMware workloads natively in the cloud. It provides a consistent infrastructure and operational experience for organizations already using VMware, enabling them to seamlessly extend their on-premises VMware environment to GCP without needing to re-architect applications. It offers a familiar environment while taking advantage of GCP's scalability, reliability, and global reach.	projects/knowledge/interview/gcp/076-what-is-vmware-enginer-offering-of-gcp.txt
gcp-security/9f74ba352668	gcp-security	hard	gcp,security,compute	What was the need of reCAPTCHA enterprise ? How do you use it ? How does it work?	reCAPTCHA Enterprise is designed to protect websites and applications from abusive activities, such as fraud, spam, and other forms of automated abuse. The need arose due to increasing instances of online abuse by bots, impacting user experience and security. It uses adaptive risk analysis to distinguish between human and automated interactions, providing frictionless user experiences while protecting against malicious activities.	projects/knowledge/interview/gcp/069-what-was-the-need-of-recaptcha-enterprise-how-do-y.txt
gcp-security/a380bef416c4	gcp-security	medium	gcp,networking,monitoring,security	What is packet mirroring in GCP ?	Packet Mirroring in GCP is a feature that allows you to capture and mirror network traffic for inspection and analysis. It copies and forwards specific packets to a collector destination for detailed examination, aiding in security monitoring, debugging, and analysis. By duplicating network traffic, you can inspect and analyze data without disrupting the live traffic flow, enhancing security and troubleshooting capabilities.	projects/knowledge/interview/gcp/064-what-is-packet-mirroring-in-gcp.txt
gcp-security/a84cb29d5ad3	gcp-security	medium	gcp,security	What is web security scanner in GCP ?	Web Security Scanner is a GCP service that helps identify security vulnerabilities in web applications. It analyzes web applications for common security vulnerabilities, including cross-site scripting (XSS), mixed content, and outdated libraries. The scanner performs automated and manual tests on web applications, providing detailed reports on identified vulnerabilities and recommended fixes.	projects/knowledge/interview/gcp/070-what-is-web-security-scanner-in-gcp.txt
gcp-security/b14a9a4f3595	gcp-security	medium	gcp,networking,iam,security	What is Identity-Aware Proxy (IAP) in GCP?	IAP is a GCP service that provides a central authentication and authorization service for applications running on GCP. It allows you to control access to web applications by verifying the identity of users and checking their permission levels before granting access. With IAP, you can secure access to your applications based on user identity and access policies without requiring a VPN.	projects/knowledge/interview/gcp/061-what-is-iap.txt
gcp-security/c071413ce43e	gcp-security	hard	gcp,iam,security	How do we do ssh using IAP ?	Secure Shell (SSH) using IAP involves setting up IAP to allow SSH connections to virtual machine instances without needing to expose them to the public internet. You can grant users or groups the necessary permissions to connect to the VM instance using SSH. This setup involves configuring IAP access, ensuring the user has the required permissions to connect via SSH, and establishing SSH connections through the GCP Console or the gcloud command-line tool.	projects/knowledge/interview/gcp/062-how-do-we-do-ssh-using-iap.txt
gcp-security/c4b573559b82	gcp-security	medium	gcp,iam,security	What is Access Context Manager in GCP ?	Access Context Manager provides centralized access control for GCP resources by defining fine-grained, attribute-based access control policies. It allows administrators to set policies based on various contextual attributes like IP address, device security status, location, and time, ensuring access to resources is granted only when specific criteria are met.	projects/knowledge/interview/gcp/075-what-is-access-context-manager-in-gcp.txt
gcp-security/c8aecb883a7e	gcp-security	medium	gcp, control-flow, iam, networking	What is Cloud Data Loss Prevention (DLP) in GCP?	Cloud DLP is a service for scanning, classifying, and redacting sensitive data across GCP services.It offers:\n* Data Inspection and Classification: Identifies sensitive data within GCP storage services.\n* Redaction and Anonymization: Allows for redacting or anonymizing sensitive data to protect privacy and confidentiality.\n* Policy Enforcement: Defines and enforces data loss prevention policies.	projects/knowledge/interview/gcp/126-what-is-cloud-data-loss-prevention-dlp-in-gcp.txt
gcp-security/d1d4ea0fdf6c	gcp-security	hard	gcp,monitoring,security	How does Security Command Center works ? or What is Security Command Center ?	Security Command Center (SCC) is a GCP service designed for centralized security risk and compliance monitoring. It provides comprehensive visibility into your GCP environment by collecting, analyzing, and alerting on security data from GCP services. SCC continuously monitors and aggregates security-oriented telemetry, including findings from various GCP services and third-party partners.	projects/knowledge/interview/gcp/066-how-does-security-command-center-works-or-what-is-.txt
gcp-security/dd39df8908b2	gcp-security	hard	gcp,iam	Difference between the above two ?	Workload Identity: Allows GCP workloads to assume identities in a secure manner for accessing GCP resources without using service account keys.\nWorkload Identity Federation: Expands the capabilities of Workload Identity by allowing integration with external identity providers, enabling a broader range of identity systems for accessing GCP resources securely.	projects/knowledge/interview/gcp/059-difference-between-the-above-two.txt
gcp-security/e295a69edf46	gcp-security	medium	gcp,iam	What are organisation policies ?	Organization Policies in Google Cloud Platform (GCP) are a set of rules and constraints that an organization administrator can define and enforce across the entire organization's GCP resources. These policies help control and govern the behavior of the resources within the organization. They can include restrictions on resource creation, configuration settings, and access control rules, ensuring compliance with regulatory requirements and organizational standards.	projects/knowledge/interview/gcp/055-what-are-organisation-policies.txt
gcp-security/e6039ff891b8	gcp-security	medium	gcp,iam,security	How does GCP ensure data security?	GCP employs multiple layers of security, including encryption at rest and in transit, IAM, and compliance certifications.\n* Encryption: Data in transit and at rest is encrypted using strong encryption protocols.	projects/knowledge/interview/gcp/101-how-does-gcp-ensure-data-security.txt
gcp-security/e88c19824d6a	gcp-security	medium	gcp,security	What is Istio in GCP?	Istio is an open-source service mesh that helps control the flow of traffic between services. It provides a uniform way to connect, manage, and secure microservices, offering features like traffic management, security, and observability. Istio's key functionalities include service discovery, load balancing, traffic control, authentication, and observability, allowing developers to have fine-grained control over their service interactions.	projects/knowledge/interview/gcp/128-what-is-istio-in-gcp.txt
gcp-security/f3ff5ed39495	gcp-security	medium	gcp,security,devops	What are source repositories in GCP ?	Google Cloud Source Repositories is a version control service that makes it easy for teams to collaborate on code. It provides a scalable, fully featured, Git-based repository for source code, allowing developers to manage and track changes across teams or even organizations. It integrates seamlessly with other GCP tools, facilitating CI/CD workflows, code review, and collaboration.	projects/knowledge/interview/gcp/086-what-are-source-repositories-in-gcp.txt
gcp-security/f83a1a64183c	gcp-security	medium	gcp,networking,iam,security	What is BeyondCorp Enterprise product of GCP ?	BeyondCorp Enterprise is Google's modern security model designed to enable secure access to applications, resources, and data without a traditional VPN. It's based on zero trust principles, eliminating the concept of a trusted internal network and ensuring every access request is authenticated, authorized, and encrypted. It provides continuous and adaptive access control, considering various factors, like device security posture, location, and context, for granting or denying access.	projects/knowledge/interview/gcp/073-what-is-beyondcorp-enterprise-product-of-gcp.txt

<!-- wiki:related:start -->
---

## Wiki Navigation

### Related Content

- GCP Compute Flashcards *(CLI)* (flashcard_deck, L1) — GCP Troubleshooting
- GCP General Flashcards *(CLI)* (flashcard_deck, L1) — GCP Troubleshooting
- GCP Kubernetes Flashcards *(CLI)* (flashcard_deck, L1) — GCP Troubleshooting
- GCP Networking Flashcards *(CLI)* (flashcard_deck, L1) — GCP Troubleshooting
- [GCP Troubleshooting](../../../../library/topics/gcp-troubleshooting/index.md) (Topic Pack, L1) — GCP Troubleshooting
- GCP Troubleshooting Flashcards *(CLI)* (flashcard_deck, L1) — GCP Troubleshooting

<!-- wiki:related:end -->
