← Professional Cloud Security Engineer: controls and evidence
03 / 8 · 40 MIN

IAP, WAF, and perimeters

Distinguish ingress control, service context, and rule observation.

Concept and mechanism

Network, application, and service controls are not interchangeable. IAP can provide authentication and authorization for the protected path, but architecture determines whether bypass exists. With IAP on the load balancer and a Cloud Run backend, the direct URL needs separate treatment; IAP directly on the Cloud Run service has different scope. Do not enable both indiscriminately. For VMs and GKE, protecting backend paths and validating signed assertions avoids trusting only a header a client can supply. Cloud Armor adds application policies with priority ordering. In simple header-only cases, smaller numbers have higher priority; body-related rules have processing nuances requiring separate analysis.

Guided application

In a fictional reporting application, the corporate domain requires login while run.app returns data directly. The main test did not demonstrate complete protection. Restrict the observed path and validate every entry point. A WAF rule in preview can match a request without enforcing a block; use that phase to evaluate impact and false positives with logging configured. Public NAT is another mechanism: it permits outbound traffic and established-connection responses rather than automatically publishing ports for unsolicited ingress. Finally, VPC Service Controls restricts service contexts and operations through perimeters. If a request violates that control, adding another IAM read role does not change the perimeter decision. Diagnose the deciding layer before expanding access.

IN PRACTICE

Allow 100 wins over deny 200 in the non-preview header-only example.

Common pitfalls

One protected URL as full coverage; preview as blocking; NAT as publishing; IAM as perimeter override.

Related topics: Federation and temporary access · IAM, deny, and inheritance · Connectivity and perimeter migration

Take this idea with you

Validate every path and each control’s effective mode.

Create account

Reference: Identity-Aware Proxy overview · Current linked guide; edition date unconfirmed (2026-09-30 inspection)