Google Cloud Professional Security Operations Engineer — knowledge map
The 128 core concepts of Google Cloud Professional Security Operations Engineer and how they connect. Click a node in the map above to explore related terms and prerequisites; the list below indexes every concept with its definition and links to its prerequisites and related concepts.
Concepts (128)
Google SecOps (SIEM/SOAR)
Formerly Chronicle. A security-operations platform with a SIEM (ingest large security logs, detect/investigate via rules) and SOAR (automate/orchestrate response via playbooks); integrated with Security Command Center.
Prerequisites: Security Command Center、SOAR
Related: SIEM
Cloud Storage
Object storage for unstructured data such as images, video, and backups.
BigQuery
Google Cloud serverless data warehouse for fast SQL analytics on petabyte-scale data.
Cloud Run
A service that runs containers serverless, scaling to zero when idle and billing only for usage.
Security Command Center
The center of security posture management that centrally visualizes misconfigurations, vulnerabilities, and threats across the cloud.
Service account
A special identity for workloads (VMs/apps) rather than humans; prefer short-lived tokens via metadata or Workload Identity Federation over downloaded keys.
Cloud Logging
A Google Cloud Observability capability for collecting, searching, and retaining logs, used for investigation and audit.
Related: Three observability pillars (metrics, logs, traces)
Encryption keys (GMEK / CMEK / CSEK)
GMEK = Google-managed default keys; CMEK = customer-managed keys via Cloud KMS (control rotation/disabling); CSEK = customer-supplied keys. Data is encrypted at rest and in transit by default.
Prerequisites: Encryption at rest、Encryption in transit
Related: Cloud KMS
Cloud Monitoring
A Google Cloud Observability capability for metrics monitoring, dashboards, and alerts.
Related: Three observability pillars (metrics, logs, traces)
Compute Engine
Google Cloud IaaS providing virtual machines (VMs) with selectable CPU/memory and OS-level control; ideal as a lift-and-shift target.
Prerequisites: Migration strategy (lift-and-shift/improve-and-move/refactor)
Three observability pillars (metrics, logs, traces)
Metrics (Cloud Monitoring, numeric trends), logs (Cloud Logging, events), and traces (Cloud Trace, request paths); correlate logs and traces by trace ID to pinpoint causes.
Related: Cloud Trace、Cloud Logging、Cloud Monitoring
Retrohunt
Applying new detection logic or newly known IOCs retroactively to previously ingested event data to find missed compromise; done with the Google SecOps rules engine or BigQuery/Cloud Logging.
Prerequisites: BigQuery、Cloud Logging、Event data and entity data、Google SecOps (SIEM/SOAR)
SOAR playbooks and case management
Google SecOps SOAR playbooks automate/orchestrate safe, routine response (enrich/isolate/ticket/notify); the case management lifecycle assigns response stages, sets escalation workflows, and assesses handoff effectiveness.
Prerequisites: Workflows、Google SecOps (SIEM/SOAR)、SOAR
SIEM
Security Information and Event Management: centrally collects logs and events from many sources (servers, network gear, apps) and correlates them to detect threats. Products like Microsoft Sentinel, Google SecOps, and Splunk fill this role.
Related: Google SecOps (SIEM/SOAR)
SOAR
Security Orchestration, Automation and Response: automates and orchestrates the post-detection response (investigation, containment, notification) to alerts from a SIEM via playbooks, cutting analyst repetitive work and response time.
Prerequisites: SIEM
Eventarc
A service that routes events from diverse sources (Pub/Sub, Cloud Storage changes) uniformly to Cloud Run/Cloud Functions.
Prerequisites: Cloud Functions、Cloud Run、Cloud Storage、Pub/Sub
Pub/Sub
A messaging service that ingests events in real time and distributes them to multiple services; used for streaming ingestion.
Encryption at rest
Encrypting data while it sits on disk or object storage. Most managed cloud storage (block/file/object/DB) offers built-in encryption integrated with the platform's key management (e.g., a KMS). A baseline defense protecting the data itself against theft or unauthorized access.
Prerequisites: Cloud Storage
Cloud Deploy
A managed continuous-delivery (CD) service for GKE, Cloud Run, and Anthos. It templates a delivery pipeline (e.g., dev → staging → prod) and provides deployment strategies like canary or blue-green, approval gates, and rollback as built-in features.
Prerequisites: Cloud Run、GKE Enterprise (Anthos)、Deployment strategies (canary/blue-green/rollback)
Related: Cloud Build
VPC firewall rules
Stateful rules that allow/deny traffic in/out of a VPC, evaluated by direction, priority, target (tags/service accounts), and source; hierarchical firewall policies exist at the org level.
Prerequisites: Service account、Cloud NGFW and hierarchical firewall
VPC Service Controls
A mechanism that prevents data exfiltration to managed services (e.g., BigQuery, Cloud Storage) via a service perimeter; a layer of control separate from IAM grants.
Prerequisites: BigQuery、Cloud Storage
Cloud Audit Logs
Audit logs recording who did what and when (admin activity, data access); used for deploy tracking and governance/compliance. Data-access auditing must be explicitly enabled.
Aggregated sink
A log sink that collects logs across an organization or folder at once and exports to BigQuery/Cloud Storage/Pub/Sub; used for SIEM forwarding and long-term retention—a higher-level form of a single-project log sink.
Prerequisites: BigQuery、Cloud Storage、Pub/Sub、SIEM
Event Threat Detection
A Security Command Center built-in that detects known threats (suspicious logins/privilege escalation) from Cloud Audit Logs (Admin Activity/Data Access), etc.; supplement cloud-specific IOCs with custom detectors.
Prerequisites: Security Command Center、Cloud Audit Logs
Toxic combinations
A Security Command Center concept: chains of configs/permissions that are low-risk alone but critical together (e.g., a public bucket + an over-privileged service account); evaluate to pre-empt attack paths.
Prerequisites: Security Command Center、Service account
Vertex AI AutoML
A Vertex AI capability that auto-builds high-quality custom ML models from tabular, text, image, or video data with minimal code. It runs neural architecture search and hyperparameter tuning under the hood to produce a model balancing accuracy against training cost. For quick SQL-only analysis, BigQuery ML can be the simpler choice.
Prerequisites: BigQuery、BigQuery ML、Vertex AI
Related: Tabular Workflows
Ops Agent
An agent installed on Compute Engine or on-prem VMs that collects detailed system metrics (CPU/memory/disk, etc.) and logs into Cloud Monitoring / Cloud Logging. It unifies the legacy separate Monitoring agent and Logging agent—use this for new deployments.
Prerequisites: Cloud Logging、Cloud Monitoring、Compute Engine
Looker Studio
A visualization (BI) tool to easily create and share reports and dashboards.
Prerequisites: Looker
Workflows
Serverless orchestration for lightweight cross-service step chaining (simple workflows); heavy dependencies use Cloud Composer.
Looker
A business intelligence (BI) tool that visualizes analytics in dashboards to support business use.
Vertex AI
A unified AI platform to build, train, deploy, and operate ML models end to end, including using foundation models.
Encryption in transit
Encrypting data while it moves across the network, typically protected with TLS. Only by pairing it with encryption at rest do you cover a piece of data's whole lifecycle (stored and moving)—satisfying both is a baseline security requirement.
Prerequisites: Encryption at rest
Curated Detections
Managed detection rule sets in Google SecOps, built from Google's threat research, that let you start detecting cloud and identity threats out of the box.
Prerequisites: Google SecOps (SIEM/SOAR)
CIDR notation
A notation expressing an IP address range by prefix length, like “/24” (256 addresses) or “/16” (65,536 addresses)—the smaller the number, the larger the range. It underlies network design across every cloud: sizing VPCs/VNets and subnets, longest-prefix-match routing, and scoping firewall-rule allows.
Prerequisites: VPC firewall rules
Ephemeral port
A temporary high-numbered port (typically 1024–65535) a client uses for the return leg of a connection. Stateless firewall rules (e.g., network ACLs) must explicitly allow this range for return traffic to work—an easily overlooked source of misconfiguration.
Prerequisites: VPC firewall rules、Port number
Cloud Interconnect
A dedicated-connection service (Dedicated/Partner) linking on-premises to Google Cloud with high bandwidth, low latency, and an SLA; choose vs the simpler encrypted-tunnel Cloud VPN by requirements.
Prerequisites: Cloud VPN
Private Google Access
A setting that lets VMs without external IPs reach Google APIs (e.g., Cloud Storage) privately; distinct in purpose from general egress via Cloud NAT.
Prerequisites: Cloud NAT、Cloud Storage
Cloud CLI emulators
Local mocks (Firestore, Pub/Sub, Spanner, etc.) provided by the Google Cloud CLI to speed local development/unit testing without connecting to the cloud (not a production substitute).
Cloud Router
A router that exchanges routes dynamically over BGP with on-prem/other networks; configure ASN, route priority/MED, and authentication, and control advertised/learned ranges with custom-advertised/learned routes.
Prerequisites: Route priority
Cloud IDS
A managed intrusion detection service (IDS) that detects network-layer intrusions and known threat signatures using Packet Mirroring; differs in scope from the cross-cutting Security Command Center.
Prerequisites: Security Command Center、Packet Mirroring
Security Health Analytics and custom modules
A Security Command Center capability for cloud security posture management (CSPM) that auto-detects misconfigurations (public buckets, over-broad firewalls); add bespoke checks via custom modules. Prevention is custom org policies.
Prerequisites: Security Command Center
Entity graph
Links users/assets/relationships (entities and context) in Google SecOps to give detection rules context and raise accuracy; enrich events with entities to speed investigation.
Prerequisites: Google SecOps (SIEM/SOAR)
Event data and entity data
Event data records "when what happened" (behavior; Cloud Audit Logs), entity data is context for "who/which asset" (AD organizational context); reconcile multiple identifiers via aliasing fields before enriching.
Prerequisites: Cloud Audit Logs
Google SecOps Risk Analytics
Assigns risk scores to detections, discovers anomalous asset/user behavior, and prioritizes threats matching a risk profile; finds anomalies via spikes in entity risk score.
Prerequisites: Google SecOps (SIEM/SOAR)
Silent source detection and SOC metrics
Silent source detection catches log sources that stopped sending data as expected (gone silent), preventing detection blind spots; measure SOC quality with KPIs like MTTD (mean time to detect) and monitor platform health with threshold alerts/notifications (Cloud Monitoring).
Prerequisites: Cloud Monitoring
Threat hunting
Proactively seeking threats—rather than waiting for alerts—by forming testable hypotheses (from incident/threat intel/posture/behavior) and querying across logs (Logs Explorer/BigQuery/Google SecOps).
Prerequisites: BigQuery、Google SecOps (SIEM/SOAR)
YARA-L detection rules
The rule language in Google SecOps for detecting suspicious behavior; combine with reference lists (lists of known values) and entity/context data to raise accuracy.
Prerequisites: Google SecOps (SIEM/SOAR)、Reference lists and risk values
Tabular Workflows
A feature that decomposes the tabular AutoML pipeline into components on Vertex AI Pipelines, letting you customize and reuse individual stages such as feature engineering or architecture search. Where plain AutoML is more black-box, Tabular Workflows targets advanced use cases needing fine control or scale over specific stages.
Prerequisites: Workflows、Vertex AI
Related: Vertex AI AutoML
Cloud DNS
A Google Cloud service that manages internal/external name resolution (domain → IP).
Cloud NAT
A service that lets VMs without external IPs make outbound calls to the internet.
Cloud VPN
A service connecting on-premises or other networks to Google Cloud over an encrypted tunnel.
Managed instance group (MIG) and instance template
A Compute Engine group that creates identical VMs from an instance template (a VM blueprint), with autoscaling and self-healing.
Prerequisites: Compute Engine
Cloud KMS
A managed key-management service to create and manage encryption keys and control rotation/disabling; the basis of CMEK.
Related: Encryption keys (GMEK / CMEK / CSEK)
BigQuery ML
A capability to create ML models and run predictions with only SQL on data in BigQuery, without moving the data.
Prerequisites: BigQuery
Gemini
Google Cloud core generative AI model for text generation, summarization, code assistance, and image understanding, embedded across services and Workspace.
Access Transparency
A feature that logs when Google support/engineering staff access customer data for reasons like support cases—capturing who, when, why, and which resource. Enabled to meet audit requirements and transparency accountability, and viewable via Cloud Logging.
Prerequisites: Cloud Logging
API Gateway (Google Cloud)
A fully managed API gateway in front of serverless backends (Cloud Run/Functions/App Engine); defined with OpenAPI to handle auth, keys, and monitoring.
Prerequisites: App Engine、Cloud Run
Cloud Billing
Links a billing account to projects to track costs, set budget alerts, and export billing data to BigQuery.
Prerequisites: Billing account and budgets、BigQuery
Cloud Build
A serverless CI service that automates fetching source, building, testing, and containerizing images. Build steps are defined in cloudbuild.yaml and can be triggered by pushes to GitHub/Cloud Source Repositories; artifacts are typically stored in Artifact Registry.
Related: Cloud Deploy、Artifact Registry
Gemini Cloud Assist
An AI assistant inside the Google Cloud console that analyzes logs, metrics, traces, and resource configuration to offer natural-language troubleshooting and architecture suggestions. Aimed at cutting the time operators spend investigating root causes across the console.
Prerequisites: Gemini
Related: Gemini Code Assist
Gemini Code Assist
An AI pair-programming feature that assists with code completion, generation, explanation, and review inside an IDE. It has a free individual tier and an Enterprise tier that can ground completions in a private codebase and add enterprise administration. Used as an extension for VS Code and JetBrains-family IDEs.
Prerequisites: Gemini
Related: Gemini Cloud Assist
IP masquerade (GKE)
A mechanism that source-NATs a GKE Pod's outbound (egress) traffic to the node's IP. By default, non-masqueraded (untranslated) destinations are RFC 1918 private ranges and link-local addresses; the ip-masq-agent configuration lets you add or change the target CIDRs. Whether this agent is auto-deployed as a DaemonSet, and its default configuration, depends on the GKE version and cluster setup (e.g., Autopilot vs. Standard, whether Dataplane V2 is in use).
Prerequisites: Dataplane V2、CIDR notation
Cloud External Key Manager (Cloud EKM)
Encrypts Google Cloud data using keys held in an external (own/third-party) key-management backend, raising key sovereignty beyond CMEK (customer-managed via Cloud KMS).
Prerequisites: Cloud KMS、Encryption keys (GMEK / CMEK / CSEK)
Deployment strategies (canary/blue-green/rollback)
Canary = release to a subset first; blue/green = instant switch between old/new environments; rollback = revert quickly on issues. Risk-limiting release techniques.
Cloud Run revisions and traffic splitting
Each deploy creates an immutable revision; traffic splitting controls the percentage sent to each revision, enabling canary release and rollback.
Prerequisites: Cloud Run、Deployment strategies (canary/blue-green/rollback)
Cloud CDN
A CDN enabled on an external Application LB backend that caches content at Google's edge; origins include MIG/Cloud Storage/Cloud Run/internet NEG. Drop stale content via cache invalidation on updates.
Prerequisites: Cloud Run、Cloud Storage
Cloud NGFW and hierarchical firewall
A next-generation firewall controlling in-VPC traffic; offers hierarchical policies inherited by org/folder, an effective policy evaluated by priority, and Enterprise-tier L7 inspection (IPS). Implement micro-segmentation with tags/service accounts.
Prerequisites: Service account
Cross-Cloud Interconnect
A service that links another public cloud to Google Cloud over a dedicated physical link without the internet; use it for multicloud connectivity when you need more bandwidth/lower latency than Cloud VPN.
Prerequisites: Cloud VPN、Cloud Interconnect
Network endpoint group (NEG)
A load balancer backend unit that groups container-native (GKE), serverless (e.g., Cloud Run), or internet endpoints; chosen vs managed instance groups (MIGs) by need.
Prerequisites: Managed instance group (MIG) and instance template、Cloud Run
VLAN attachment
The logical link between a Cloud Interconnect and a VPC (Cloud Router); after creating the physical Interconnect, a VLAN attachment carries traffic to the actual VPC.
Prerequisites: Cloud Interconnect、Cloud Router
Confidential Computing
Processes data in use (in memory) within encrypted VMs/nodes, protecting it from the host/other tenants; a different surface (data in use) than encryption at rest/in transit.
Prerequisites: Encryption at rest、Encryption in transit
restricted Google access
Limits reachable Google APIs to only allowed services (via restricted.googleapis.com), aligning with VPC Service Controls to block exfiltration paths; used with Private Google Access.
Prerequisites: Private Google Access、VPC Service Controls
Port number
A 16-bit number identifying which service is running on a given IP address (e.g., HTTP uses 80, HTTPS uses 443, SSH uses 22). Carried in TCP/UDP headers, and firewall/security-group rules allow or deny traffic based on source/destination port.
Prerequisites: HTTPS
Reference lists and risk values
Reference lists hold known-bad values, watchlists, and risk values referenced by detection rules; rules use them to weight/prioritize threats matching a risk profile.
UDM and parsers
UDM (Unified Data Model) is the unified schema Google SecOps normalizes ingested logs into, enabling source-independent search/detection; parsers extract fields from raw logs into UDM (modify/extend as needed).
Prerequisites: Google SecOps (SIEM/SOAR)
Billing account and budgets
The unit that pays costs; link projects to it (one account, many projects). Budgets and alerts only notify at thresholds and do not auto-stop spending.
Organization Policy
A mechanism that inherits and enforces constraints down the resource hierarchy for consistent org-wide rules (e.g., disallow creation outside certain regions); distinct from IAM grants.
Prerequisites: Resource hierarchy
Cloud Storage classes
Classes by access frequency: Standard (frequent)/Nearline (~monthly)/Coldline (~quarterly)/Archive (long-term rare). Less access = cheaper storage but pricier retrieval.
Prerequisites: Cloud Storage
Storage Transfer Service
A managed service to transfer large or continuous data into Cloud Storage; for small data, the gcloud/bq CLI is simpler.
Prerequisites: Cloud Storage
VPC Network Peering
Directly connecting two VPC networks so they can communicate with each other.
Prerequisites: Virtual Private Cloud (VPC)
Transfer Appliance
An offline transfer service that ships large data on a physical device for ingestion into Cloud Storage; suits volumes where network transfer is impractical.
Prerequisites: Cloud Storage
App Engine
A fully managed web app platform (PaaS) to publish apps without managing servers, letting you focus on development.
Cloud Functions
A serverless functions service for event-driven small tasks, such as running when a file is uploaded.
Cloud SQL
A managed relational database compatible with MySQL/PostgreSQL/SQL Server, for typical business apps.
Data residency and sovereignty
Data residency = the geographic location (region) where data is stored; data sovereignty = data being subject to a country laws.
Firestore
A scalable document NoSQL database for mobile and web app data.
GKE Enterprise (Anthos)
A platform to operate and manage containers consistently across on-premises and multiple clouds, enabling hybrid and multicloud.
Resource hierarchy
The Google Cloud hierarchy of Organization → Folder → Project → resources; the project is the basic billing/permission unit and policies inherit down the hierarchy.
Sensitive Data Protection (Cloud DLP)
A service that automatically discovers, classifies, and masks sensitive data such as PII in stored data.
Spanner
A distributed relational database combining global strong consistency and high availability, ideal for global core systems.
Spot VM
A Compute Engine VM offered at a deep discount in exchange for possible preemption; used for cost optimization of interruption-tolerant batch work.
Prerequisites: Compute Engine
Connection tracking
How a stateful firewall (e.g., a security group) remembers established connections in a state table and automatically allows their return traffic. Unlike stateless rules, it removes the need to separately open the ephemeral-port range for the return leg.
Prerequisites: Ephemeral port
Model Garden
A Vertex AI catalog to browse and choose among diverse foundation models (Google, open, third-party).
Prerequisites: Vertex AI
Access Approval
A feature that requires the customer's explicit pre-approval before Google staff can access data, e.g., for support. Where Access Transparency is an after-the-fact log, Access Approval adds an upfront approval gate—the two are combined for stronger sovereignty controls.
Prerequisites: Access Transparency
Classic VPN
A legacy, single-tunnel IPSec VPN gateway with no SLA guarantee. It comes in route-based (dynamic) and policy-based (static traffic-selector) variants, with the latter kept mainly for compatibility with specific peer network devices. Google deprecates it in favor of HA VPN for new builds.
Prerequisites: HA VPN
Cloud Code
An extension built into IDEs like VS Code and IntelliJ. It helps author Kubernetes manifests and Dockerfiles, deploy to GKE/Cloud Run directly from your local machine, and live-debug on a remote cluster—all from within the editor.
Prerequisites: Cloud Run
Cloud Endpoints
An API management service that manages OpenAPI/gRPC APIs via the Extensible Service Proxy, adding auth, monitoring, and quotas.
Prerequisites: gRPC
Deployment Manager
Google Cloud's native Infrastructure as Code service (YAML/Jinja/Python templates). It is deprecated and reaches end of support on 2026-03-31; migrate to the Terraform-based Infrastructure Manager or another IaC tool.
Prerequisites: Infrastructure Manager
Filestore
A fully managed NFS file storage that mounts as a shared file system from Compute Engine VMs or GKE, providing low-latency shared storage.
Prerequisites: Compute Engine
HA VPN
Google's recommended IPSec VPN, providing a 99.99% availability SLA via two redundant tunnels (each with its own external IP). Used to connect to on-prem, other clouds, or other VPCs, and assumes dynamic routing via BGP. The default choice for new deployments.
Virtual Private Cloud (VPC)
Google Cloud's software-defined network. A global resource that holds regional subnets in one network; routes, firewalls, and peering control traffic.
Workload Identity Federation (GCP)
A mechanism that trusts an external identity provider outside Google Cloud—AWS, Azure, on-prem, or CI/CD like GitHub Actions—and exchanges its issued tokens for temporary Google Cloud credentials. Used for external system integrations where you want to avoid downloading and distributing service-account keys.
Prerequisites: Service account
Dataplane V2
GKE's eBPF-based networking data plane. It enforces Kubernetes NetworkPolicy (Pod-to-Pod L3/L4 traffic control) efficiently at the kernel level and also provides visibility via flow logs. It has become the default for new clusters on recent GKE versions and runs with less overhead than the older iptables-based implementation.
HTTPS
HTTP carried on top of TLS. Unlike plain HTTP, the traffic is encrypted, preventing eavesdropping or tampering along the path. Browsers verify the certificate to confirm the server's legitimacy, and it's now the standard way sites communicate.
Principle of least privilege
A design principle that grants each identity (person, app, or service) only the minimum permissions needed to do its job. Excess privilege widens the blast radius of a mistake or breach, so it is continuously tightened through IAM roles, policies, and permission boundaries.
Prerequisites: Blast radius
Cloud Trace
A distributed-tracing service that follows request paths (spans) across services to find latency bottlenecks; a different observability axis from metrics (Monitoring) or logs (Logging).
Related: Three observability pillars (metrics, logs, traces)
Infrastructure Manager
A Google Cloud service that runs Terraform as managed IaC, making infrastructure reproducible and reviewable/auditable via CI/CD and PRs.
Migration strategy (lift-and-shift/improve-and-move/refactor)
Lift-and-shift = move as-is (fastest, least change); improve-and-move = slight optimization; refactor = rebuild cloud-native (most effort, biggest payoff). Choose by requirements.
Application Default Credentials (ADC)
The standard way an app resolves credentials to authenticate to Google Cloud; combine with service accounts or Workload Identity Federation to avoid hardcoded keys.
Prerequisites: Service account
Artifact Registry
A registry to store and manage container images and language packages; the destination for artifacts built by Cloud Build.
Related: Cloud Build
Cloud SQL Auth Proxy
A proxy for secure Cloud SQL connections using IAM auth and encryption without exposing a public IP; the recommended way for apps to connect to the DB.
Prerequisites: Cloud SQL
gRPC
A low-latency, typed (Protocol Buffers) RPC framework over HTTP/2, suited to internal service-to-service calls; choose REST for public web.
Signed URL
A URL granting time-limited, scoped access to a Cloud Storage object without making it public; different from making a whole bucket public.
Prerequisites: Cloud Storage
Artifact Analysis
Scanning that detects known vulnerabilities in container images/packages. Distinct from Binary Authorization (deploy-only-if-signed); combine detection with enforcement.
Prerequisites: Binary Authorization
Synthetic monitors
Actively and periodically probe endpoints/workflows from the user perspective (external monitoring); pair with passive monitoring to catch issues proactively.
Prerequisites: Workflows
Cloud DNS routing policies and split-horizon
Advanced Cloud DNS resolution: geolocation (vary by source region) and failover (switch to backup on primary failure) routing policies, plus split-horizon DNS resolving the same name differently via public/private zones.
Prerequisites: Cloud DNS
Dynamic routing mode (global/regional)
A VPC setting that determines how far BGP routes learned by Cloud Router propagate: regional stays within one region; global propagates to all regions. Use global to span multiple regions.
Prerequisites: Cloud Router
Hybrid DNS (forwarding zones/inbound policy/DNS peering)
Configurations for bidirectional name resolution between on-prem and Cloud DNS: forwarding zones query on-prem from cloud, inbound server policy resolves cloud from on-prem, and DNS peering references a zone in another VPC.
Prerequisites: Cloud DNS
Packet Mirroring
Replicates traffic in full and sends it out-of-band to self-managed IDS/IPS collectors; more precise than sampled VPC Flow Logs. Distinct from inline inspection (multi-NIC NVA) that blocks on the path.
Route priority
A value that decides which route is chosen when multiple share a destination; a lower value wins. Combine with network tags to scope where it applies.
Secure Web Proxy
A proxy that allowlists egress by URL/SNI; unlike Cloud NAT (general internet egress), it controls "where egress is allowed" at the application layer.
Prerequisites: Cloud NAT
Access Context Manager
Defines access boundaries by context (access levels: device, source IP, region); integrates with VPC Service Controls and IAP for zero-trust-style control.
Prerequisites: VPC Service Controls
Cloud HSM
Protects encryption keys in FIPS 140-2 Level 3 tamper-resistant hardware (HSM); chosen when higher assurance than software keys is required; usable as a CMEK backend.
Prerequisites: Encryption keys (GMEK / CMEK / CSEK)
Regionalization (resource location constraint)
Enforces data-residency requirements—confining storage/processing to a specific country/region—via the organization-policy resource location constraint; used for data-sovereignty compliance.
Prerequisites: Data residency and sovereignty
Sensitive data protection (PII / masking)
Protecting sensitive data such as PII (personally identifiable information) and PHI: discover/classify with Macie, then protect via encryption, access control, and minimization. Masking/tokenization hides values, and handling varies by data classification; also prevent sensitive data leaking into logs.
Blast radius
The scope of impact from a failure, mistake, or breach. Kept small via account separation, multiple Regions/AZs, least privilege, and cell-based partitioning. Limiting blast radius is fundamental to resilience and security.
Subnet mask
A value marking the boundary between the network and host portions of an IP address (e.g., 255.255.255.0)—the dotted-decimal counterpart to a CIDR prefix length, still used in on-prem network gear and some cloud configuration screens.
Prerequisites: CIDR notation

