What this objective tests
GCDL Trust and security with Google Cloud — Key Topics
Match scenarios to Google Cloud controls: Cloud IAM roles and policies, VPC Service Controls, Cloud KMS and CMEK, Security Command Center, and Compliance Reports Manager. Get the shared responsibility split right: Google secures the infrastructure, you secure data, access, and configuration.
- Applying the shared responsibility model to Google Cloud versus customer-controlled security duties
- Choosing IAM roles, service accounts, and least-privilege policies for a given access scenario
- Selecting encryption options: default Google-managed keys, CMEK via Cloud KMS, or CSEK
- Identifying Security Command Center, Cloud Armor, and Cloud Audit Logs for monitoring and compliance