2Securing communications and establishing boundary protection
- 2.1Perimeter security and edge defense
Understand network perimeter controls (Cloud NGFW rules/policies, Identity-Aware Proxy [IAP], load balancers, Certificate Authority Service), Cloud NGFW application-layer (L7) inspection, private/public IP, web application firewall (Google Cloud Armor), Secure Web Proxy, Cloud DNS security settings, and continually monitoring/restricting configured APIs.
- 2.2Boundary segmentation and private connectivity
Understand security properties of VPC/VPC peering/Shared VPC/firewall, network isolation and data encapsulation for N-tier apps, VPC Service Controls use cases/config, private connectivity between VPCs/projects (Shared VPC, VPC peering, Private Google Access for on-prem), encrypted connectivity between data centers and VPC (HA VPN, Cloud Interconnect), private connectivity to Google APIs (Private Google Access, restricted Google access, Private Service Connect), and egress via Cloud NAT.

