The GCP CDL security and trust domain covers roughly 10% of the exam. The key questions are: how Google Cloud protects data, how IAM controls access, and how compliance is achieved.
Security Fundamentals — CIA Triad
Every security system aims to achieve three properties:
| Principle | Meaning | Example | |-----------|---------|---------| | Confidentiality | Only authorized people can access data | Encryption, access control | | Integrity | Data cannot be altered without authorization | Hash verification, digital signatures | | Availability | Services are accessible when needed | Redundancy, DDoS protection |
Think of a medical database: only authorized doctors can access records (confidentiality), diagnoses must not be altered (integrity), and it must always be accessible in emergencies (availability).
Defense-in-Depth
Never rely on a single security control. Apply multiple layers — if one fails, the others still protect you.
Google Cloud security layers (example): Network perimeter: Cloud Armor blocks DDoS attacks Network interior: VPC firewall rules control traffic Access control: Cloud IAM restricts authenticated users Data: Encryption protects data itself Audit: Cloud Logging records all activity
!Google Cloud defense-in-depth security layers
Cloud IAM — Access Control
Cloud IAM defines "who can do what on which resource." Three key components:
Principals (Who?)
| Principal Type | Description | Example | |----------------|-------------|---------| | Google Account | Individual user | user@gmail.com | | Service Account | Used by apps or VMs | my-app@project.iam.gserviceaccount.com | | Google Group | Collection of users | dev-team@company.com | | Workspace Domain | Entire organization | company.com |
Roles (What can they do?)
| Role Type | Scope | Examples | |-----------|-------|---------| | Basic roles | Entire project | Owner, Editor, Viewer | | Predefined roles | Service-specific | roles/storage.objectViewer | | Custom roles | Hand-picked permissions | Only the permissions you need |
Principle of Least Privilege: Grant only the minimum permissions needed. Basic roles (Owner, Editor) are too broad for production — use predefined or custom roles instead.
Encryption
Google Cloud encrypts all customer data by default with no extra configuration required.
| Encryption Type | When | Description | |----------------|------|-------------| | At-Rest | Data stored on disk | Default, Google-managed keys | | In-Transit | Data moving over networks | TLS/SSL automatically applied | | CMEK | Compliance, key control needs | Customer manages keys in Cloud KMS | | CSEK | Highest key ownership | Customer generates and provides keys directly |
CMEK vs CSEK: CMEK keys live in Cloud KMS (Google infrastructure). CSEK keys are fully owned and controlled by the customer — Google never stores them.
Security Services
| Service | Layer | Key Capabilities | |---------|-------|-----------------| | Cloud Armor | Network | DDoS protection, WAF, IP blocking, geo-based rules | | Security Command Center | Unified dashboard | Vulnerability detection, threat detection, misconfiguration alerts | | Cloud DLP | Data | Auto-detect/mask PII (emails, credit cards, SSNs, etc.) | | 2-Step Verification | Account | Requires extra authentication factor beyond password |
Cloud Armor protects against DDoS attacks (which overwhelm servers with traffic) and web application attacks (SQL injection, XSS) via its WAF functionality.
Security Command Center is your unified security dashboard — it automatically detects misconfigurations (like publicly accessible buckets), vulnerabilities, and threats.
Cloud DLP automatically finds sensitive data in databases or files and can mask, anonymize, or encrypt it.
Google's 6 Trust Principles
Google publicly commits to these principles for handling customer data — frequently tested:
Customers own their data — Google does not Google never sells customer data Google never uses customer data for advertising All data is encrypted by default Google protects against unauthorized government access Transparency reports are published regularly
Data Sovereignty
Data sovereignty means the laws of the country where data is stored or processed apply to it. For example, EU citizen data may need to stay within the EU under GDPR.
Google Cloud lets you choose regions to control exactly where data is stored. You can pin data to a specific region (e.g., Seoul: asia-northeast3) to satisfy local legal requirements.
Compliance Certifications
Google Cloud holds certifications for major international standards: ISO 27001 (information security management), SOC 1/2/3 (internal controls audits), GDPR (EU data protection), HIPAA (US healthcare), PCI DSS (payment card data).
Compliance Reports Manager: Download audit reports, certificates, and compliance documents directly from the Google Cloud Console.
Exam Key Points
"Authorized access only / no tampering / always accessible" -- CIA Triad (Confidentiality/Integrity/Availability)
"Multiple security layers, each backs the others up" -- Defense-in-Depth
"Who can do what on which resource" -- Cloud IAM
"Only the minimum permissions needed" -- Principle of Least Privilege
"Account used by apps or VMs" -- Service Account
"DDoS protection and WAF" -- Cloud Armor
"Unified security dashboard, vulnerability detection" -- Security Command Center
"Detect and mask sensitive/PII data" -- Cloud DLP
"All data encrypted at rest by default" -- Google default encryption
"Customer manages keys in Cloud KMS" -- CMEK
"Customer generates and provides their own keys" -- CSEK
"Customer owns data, not sold, not used for ads, default encryption" -- Google Trust Principles
"Data must be stored in a specific country by law" -- Data Sovereignty
"Download ISO/SOC/GDPR/HIPAA audit reports" -- Compliance Reports Manager