Written in a simple, and developer-focused style, this book will give you the tools and the knowledge you need to ace the GCP Professional Cloud Security Engineer certification exam. The approach is two-fold: introducing and implementing all GCP cloud security concepts and controls based on the certification exam objectives, and demonstrating how these concepts can be applied to real-world scenarios.
Your study begins by introducing the concept of cloud identities in GCP, with a focus on the different identity types user accounts, service accounts, groups, and domains) and how separation of duties is implemented with access controls and Identity and Access Management (IAM).
Emphasis is placed on the unique GCP approach to managing resources, with its clear distinction between resource ownership and resource billing. Following the defense in depth principle, the book then shifts focus to network security and introduces the different types of constructs that enable micro-segmentation, as they are implemented in a software-defined network. As a natural progression to your security study with GCP, a chapter fully devoted to data protection is included. You will learn how to leverage the Data Loss Prevention (DLP) application programming interface (API) to prevent access to your workloads' sensitive data from unauthorized use. Examples on how to use the DLP API are provided using the Go language, which is becoming widely adopted in the developer community due to its simplicity, and high-performance networking and multi-processing capabilities. Encryption at rest, in use, and in transit is covered as well with a brief overview of how GCP implements confidential computing. The book concludes with an examination of the GCP services you need to know to monitor, audit, and ensure compliance with the laws and regulations where your workloads and infrastructure operate.
By the end of the book, you will have acquired the knowledge and the confidence to pass the GCP Professional Cloud Security Engineer certification, and most importantly to successfully design, architect, and engineer security solutions with the Google Cloud Platform.
What You Will Learn
- The five security principles and how they can be used to drive the development of modern security architectures in Google Cloud
- How to secure identities with Cloud Identity and Identity & Access Management (IAM)
- How to secure the network with segmentation and private connectivity
- How to protect sensitive data with the Data Loss Prevention (DLP) API and encryption
- How to monitor, log, audit, and troubleshoot security incidents with the Google Cloud Operations Suite
- How to ensure compliance and address regulatory concerns
Who This Book Is For
A diverse audience, including software engineers specializing in DevOps, SecOps, and DataOps, who possess expertise in the Software Development Life Cycle (SDLC) methodologies within Agile teams. It also targets software architects with proficiency in various domains such as Security, Network, Solution, Data, Infrastructure, Cloud, and Enterprise Architecture.