0%

Explore Courses Defend What Matters

Your Bag

Google Cloud Platform (GCP) Security

04 Cloud Security

Google Cloud Platform (GCP) Security

Secure GCP using its resource hierarchy, IAM bindings, VPC Service Controls, and the logging stack that makes an incident reconstructable.

Levels
04
Skill Range
Beginner Expert
Track
Cloud Security
Lifetime Access
Google Cloud Platform (GCP) Security
From 278CREDS

GCP organises permissions differently from AWS and Azure, and that difference is where mistakes happen. This course begins with the resource hierarchy of organisation, folders, and projects, and shows how IAM bindings inherit down it, including the service account impersonation chains that turn a small grant into a large one. You will design VPC networks with firewall rules and Private Google Access, apply VPC Service Controls to build a perimeter around data services, and manage keys with Cloud KMS. Workload identity, GKE hardening, and secure CI/CD access are covered for teams running containers. Detection uses Cloud Logging, Cloud Audit Logs, and Security Command Center, with a practical incident reconstruction exercise.

Curriculum

Learning Path

Each level is enrolled separately. Work through them in order, or start at the level that matches your experience.

  1. Level 01

    Beginner

    278 CREDS

    Purpose

    Learn the GCP resource hierarchy, since that is where its permission mistakes come from.

    Outcome

    You can read GCP IAM and see what a principal can actually do.

    What You'll Learn
    • Map the organisation, folder, and project hierarchy and how IAM inherits down it.
    • Read IAM bindings and understand effective permissions.
    • Spot where inheritance grants more than intended.
  2. Level 02

    Intermediate

    411 CREDS

    Purpose

    Design GCP networking and contain data services behind a perimeter.

    Outcome

    You can secure GCP networking and wall off its data services.

    What You'll Learn
    • Configure VPC firewall rules and Private Google Access.
    • Apply VPC Service Controls to build a perimeter around data services.
    • Manage keys with Cloud KMS and control their use.
  3. Level 03

    Advanced

    734 CREDS

    Purpose

    Harden GKE and secure the service account chains that turn a small grant into a large one.

    Outcome

    You can harden GKE and shut down impersonation-based escalation.

    What You'll Learn
    • Secure workload identity and GKE against common misconfigurations.
    • Trace and break service account impersonation chains.
    • Lock down CI/CD access to the cluster.
  4. Level 04

    Expert

    997 CREDS

    Purpose

    Build GCP detection and reconstruct an incident from the logging stack.

    Outcome

    You can detect and reconstruct an incident inside GCP.

    What You'll Learn
    • Configure Cloud Logging, Cloud Audit Logs, and Security Command Center.
    • Correlate events across projects into a single account of what happened.
    • Reconstruct an incident and identify the entry point.