Lộ trình
Google CloudAssociateTuần 4: Tối ưu & vận hànhBài 24 / 30

Ngày 24: Bảo mật hạ tầng

Thời lượng: 45 phút
Mục tiêu: 2 nhiệm vụ chính
Tiến độ lộ trình
gcp-acengày 24
hoàn thành24 / 30 bài
Bối cảnh bài học

Bảo vệ hạ tầng GCP bằng threat model và control mapping: IAM, firewall, Cloud Armor, SCC, encryption, logging và incident response.

đọc hiểuthực hànhcheckpoint
Bài giảng hôm nay

Học hiểu, rồi mới thực hành

Bảo vệ hạ tầng GCP bằng threat model và control mapping: IAM, firewall, Cloud Armor, SCC, encryption, logging và incident response.

Bắt đầu đọc bài giảng

Nhiệm vụ bài học hôm nay

  • Tìm hiểu Cloud Armor, Security Command Center
  • Học các nguyên tắc bảo mật cơ bản trên GCP
Instructor walkthrough

Bài giảng chi tiết: từ bài toán đến bằng chứng

Scenario xuyên suốt

Một API public bị credential abuse và request độc hại; team định mở firewall, cấp Owner và bật mọi log mà không biết control nào thuộc layer nào. Bài học biến security recommendation thành threat → control → evidence → response.

01Đọc bài toán

Xác định actor, workload, constraint và trạng thái cuối cần đạt.

02Vẽ luồng / boundary

Chỉ ra request, dependency, identity và failure domain trước khi chọn công cụ.

03Chọn và thực hành

Thay đổi nhỏ nhất trong lab cô lập; command nào cũng phải nói rõ nó kiểm tra điều gì.

04Kiểm chứng / recovery

Đối chiếu trạng thái thực tế, tạo một failure variant và ghi cách hoàn tác.

Cách nối lý thuyết với thực tế
  • IAM bảo vệ identity/action; VPC firewall bảo vệ network flow; Cloud Armor bảo vệ HTTP(S) edge/WAF/DDoS policy; không control nào thay toàn bộ control khác.
  • Security Command Center giúp posture/finding visibility; finding cần triage, owner, severity, remediation và verification.
  • Encryption at rest/in transit, key management và secret handling có scope/lifecycle khác nhau.
  • Threat model cần asset, trust boundary, threat, likelihood/impact, preventive/detective control và residual risk.

Threat trước control

Bắt đầu bằng asset và trust boundary: user/API edge, workload identity, private data, admin path. Sau đó map threat vào layer phù hợp. IAM quyết định ai được làm gì; firewall quyết định network flow; Cloud Armor lọc HTTP edge; SCC cung cấp posture/finding visibility; logging/monitoring cung cấp evidence.

Incident runbook

Một runbook tốt có detect → validate → contain → eradicate/rotate → recover → verify → learn. Preserve timeline/log trước containment, tránh xóa dữ liệu hoặc cấp quyền rộng để chữa cháy. Credential leak cần revoke/rotate và truy vết usage; HTTP abuse cần edge policy/rate limit/health evidence.

Bài tập

Lập threat/control/evidence matrix cho public API và tabletop hai incident. Ghi action owner, severity, rollback, residual risk và cleanup. Nếu không có security sandbox, dùng policy/finding read-only và design có pass criteria.

Terminal reference

Command list và cách dùng

Chạy từng lệnh theo đúng thứ tự. Trước các lệnh có thể tạo hoặc thay đổi tài nguyên, hãy kiểm tra profile, account và region.

Commands · read-only checkpoints
gcloud compute security-policies list --project=LAB_PROJECT_ID --format="table(name,type,description)"
gcloud scc findings list organizations/ORG_ID --location=global --format="table(finding.category,finding.severity,state,resourceName)"
gcloud projects get-iam-policy LAB_PROJECT_ID --format="yaml(bindings)"
gcloud logging read "protoPayload.methodName!=" --project=LAB_PROJECT_ID --limit=20 --format="table(timestamp,protoPayload.authenticationInfo.principalEmail,protoPayload.methodName,resource.labels)"
Hands-on lab

Thực hành theo scenario

  1. Vẽ threat model cho public Cloud Run/API, private database và admin path: asset, actor, boundary, attack path và impact.
  2. Map từng threat với IAM role/scope, firewall, Cloud Armor, SCC finding, logging/alert, secret/crypto và owner; inspect policy/finding metadata read-only.
  3. Mô phỏng incident credential leak hoặc HTTP abuse bằng tabletop: detect → validate → contain → rotate/revoke → recover → evidence review.
  4. Không tắt security control production hoặc tạo rule mở rộng để test. Cleanup test policy/alert/binding và ghi residual risk.
Evidence checkpoint

Kiểm chứng kết quả

Không coi lệnh chạy thành công là đủ. Hãy đối chiếu output với trạng thái mong đợi:

  • Threat model có asset/boundary/impact.
  • Control được gắn đúng layer và scope.
  • Finding/incident có owner, severity, evidence và action.
  • Credential/secret/log safety rõ.
  • Có containment/rollback/cleanup và residual risk.
Transfer to exam / production

Bẫy thường gặp và trade-off

ACE phân biệt Cloud Armor với firewall, IAM với network control và SCC với remediation tự động. Đáp án tốt phải giải quyết threat cụ thể và nêu evidence.

Checkpoint · 3 phút

Kiểm tra nhanh

Câu hỏi: API public bị HTTP request độc hại nhưng VM vẫn cần private database. Control ưu tiên nào phù hợp?

Kết thúc bài

Checklist trước khi sang Ngày 2