← Professional Cloud Security Engineer: controls and evidence
04 / 8 · 40 MIN

Connectivity and perimeter migration

Evaluate data and transport boundaries with representative evidence.

Concept and mechanism

VPC Service Controls adds a contextual layer independent of IAM for specified services and resources. A private endpoint does not demonstrate that every API-accessible data destination belongs to authorized scope. Analyze operations, resources, ingress, and egress alongside routes. Dry run evaluates proposed configuration without replacing enforced protection. Logs are differential: requests already denied by enforcement do not necessarily generate the dry-run violation the team seeks. Absence of that record does not prove the new design would allow the operation. Define a matrix of expected flows and use representative evidence for each, including those that must remain denied.

Guided application

In a fictional migration, a project must move from perimeter A to B. Respect single membership per mode and sequence dry-run configuration before changing enforcement. Access levels have no automatic dry-run copy; changing a level used in production can affect actual protection. For hybrid connectivity, a private Interconnect link does not mean automatic end-to-end encryption. Confirm the requirement and scope of the chosen mechanism, such as MACsec, VPN, or TLS. PSC endpoints should also be interpreted through the published service: consuming it creates neither general network transitivity nor unrestricted producer ingress into the consumer. Every direction, identity, and data class should have a verifiable justification.

IN PRACTICE

No dry-run log can mean enforcement already denied the request rather than the new design allowing it.

Common pitfalls

Private endpoint as authorized destination; dry run as complete coverage; Interconnect as TLS; PSC as general peering.

Related topics: Federation and temporary access · IAM, deny, and inheritance · IAP, WAF, and perimeters

Take this idea with you

Separate transport, authorization, and data boundaries in architecture decisions.

Create account

Reference: VPC Service Controls overview · Current linked guide; edition date unconfirmed (2026-09-30 inspection)