Fundamental 10 Steps 8時 10分 44クレジット
Security is an uncompromising feature of Google Cloud Platform services, and GCP has developed specific tools for ensuring safety and identity across your projects. In this fundamental-level quest, you will get hands-on practice with GCP’s Identity and Access Management (IAM) service, which is the go-to for managing user and virtual machine accounts. You will get experience with network security by provisioning VPCs and VPNs, and learn what tools are available for security threat and data loss protections.
Prerequisites
Although this quest will teach you the fundamentals of Identity and Access Management (IAM) and Security in GCP, you will still need hands-on experience with the platform's core tools and services. It is recommended that the student have at least earned a Badge by completing the GCP Essentials and/or the Baseline: Infrastructure Quests before beginning.Quest Outline
Cloud IAM: Qwik Start
Google Cloud IAM は、Cloud Platform サービスに対するアクセス制御を 1 つのシステムに統合し、一貫性のある一連の操作を提供します。Manage Access Control with Google Cloud IAM で短い動画をご覧ください。
IAM Custom Roles
Cloud IAM provides the right tools to manage resource permissions with minimum fuss and high automation. You don't directly grant users permissions. Instead, you grant them roles, which bundle one or more permissions. This allows you to map job functions within your company to groups and roles.
Controlling Access to Google Cloud Functions
In this lab, you secure a Cloud Function so that only specific users authenticated by Cloud Identity & Access Management (IAM) can use it.
Cloud Security Scanner: Qwik Start
The Cloud Security Scanner identifies security vulnerabilities in your Google App Engine web applications.
Service Accounts and Roles: Fundamentals
In this hands-on lab, you will learn how to create and manage Service Accounts
VPC Network Peering
Google Cloud Platform (GCP) Virtual Private Cloud (VPC) Network Peering allows private connectivity across two VPC networks regardless of whether or not they belong to the same project or the same organization.
Data Loss Prevention: Qwik Start - Command Line
Google Cloud Dataprep is an intelligent data service for visually exploring, cleaning, and preparing data for analysis.
Data Loss Prevention: Qwik Start - JSON
Google Cloud Dataprep is an intelligent data service for visually exploring, cleaning, and preparing data for analysis. Watch the short video Discover and Protect Sensitive Data wth Cloud Data Loss Prevention.
Cloud KMS の使い方
このラボでは、安全な Cloud Storage バケットの設定、Key Management Storage を使用した鍵と暗号化データの管理、Cloud Storage 監査ログの表示など、Google Cloud Security および Privacy API の高度な機能を扱います。
Setting up a Private Kubernetes Cluster
Hands-on lab for creating a private cluster in the cloud environment. In a private cluster, nodes do not have public IP addresses, so your workloads run in an environment that is isolated from the Internet. Prerequisites: Experience with Kubernetes Clusters, and CIDR-range IP address.
Building a High-throughput VPN
In this lab you will learn how to create secure, high-throughput VPN and test the speed.