When you enroll in this course, you'll also be enrolled in this Professional Certificate.
Learn new concepts from industry experts
Gain a foundational understanding of a subject or tool
Develop job-relevant skills with hands-on projects
Earn a shareable career certificate from Google Cloud
There are 4 modules in this course
Two courses down, three to go – you’re well on your way! This is the third course of the Google Cloud Cybersecurity Certificate. You’ll delve into the key aspects of identity management and access control in cloud computing, including security principles like least-privilege and separation-of-duties, and the crucial elements of AAA: authentication, authorization, and auditing. AAAnd…let’s go to it! ← See what we did there?!
In this module, you’ll deep dive into the crucial aspects of identity management and access control in cloud computing, covering security principles like least-privilege and separation-of-duties, and the crucial elements of AAA: authentication, authorization, and auditing. You'll explore various access control methods, credential management, and certificate handling, key to securing cloud applications.
Manny: A day in the life of a red team security engineer•2 minutes
Welcome to module 1•1 minute
Core principles of identity management•4 minutes
Authentication, authorization and auditing (AAA)•5 minutes
Credential handling and service accounts•5 minutes
Access controls in the cloud•5 minutes
Perimeter protection•6 minutes
Common attack vectors•3 minutes
Zero trust•7 minutes
Wrap-up•2 minutes
10 readings•Total 130 minutes
Course 3 overview•10 minutes
Helpful resources and tips•10 minutes
Lab technical tips•10 minutes
Explore your course 3 scenario: Cymbal Bank•10 minutes
Uses for identity management measures•10 minutes
Cloud access control in action•20 minutes
Trust boundaries•20 minutes
Guide to firewall rules•20 minutes
Zero trust policies and complementary controls•10 minutes
Glossary terms from module 1•10 minutes
5 assignments•Total 84 minutes
Module 1 challenge•50 minutes
Test your knowledge: Access management•10 minutes
Test your knowledge: Types of access controls•8 minutes
Test your knowledge: Perimeter protection•8 minutes
Test your knowledge: Zero trust•8 minutes
2 app items•Total 180 minutes
Create a role in Google Cloud IAM•90 minutes
Access a firewall and create a rule•90 minutes
1 plugin•Total 15 minutes
Accessing and completing labs•15 minutes
Threat and vulnerability management
Module 2•7 hours to complete
Module details
Get ready for another action-packed adventure! In this module, you'll transform into a threat-hunting detective. Uncover hidden vulnerabilities, pinpoint risks with precision, and deploy cunning mitigation strategies. You'll unlock the secrets of asset management, discovering tools and techniques for safeguarding your resources like a seasoned pro. And get ready to crack the code on secure configuration, building an impenetrable fortress within the cloud.
What's included
13 videos8 readings6 assignments1 app item
Show info about module content
13 videos•Total 61 minutes
Welcome to module 2•2 minutes
Introduction to threat management•5 minutes
Eyre: Secure cloud assets•2 minutes
Asset and resource management•6 minutes
Steps for asset management•7 minutes
Vulnerability remediation and posture management•4 minutes
Vulnerability remediation and posture management in software development•5 minutes
IT automation tools for posture management•6 minutes
Patching and rehydration•6 minutes
Compare and contrast: Patching and rehydration•5 minutes
Trends in vulnerability and threat management•7 minutes
Reports and assessments for threat and vulnerability management•5 minutes
Wrap-up•2 minutes
8 readings•Total 150 minutes
Threat and vulnerability management assessments•20 minutes
Posture management tools and techniques•20 minutes
IT automation tools for security configuration management•20 minutes
Guide to web application security scanning•20 minutes
Rehydration keeps systems up-to-date•20 minutes
Trends in security: Artificial Intelligence (AI), machine learning (ML), and Internet of things (IoT)•20 minutes
Glossary terms from module 2•10 minutes
6 assignments•Total 96 minutes
Module 2 challenge•50 minutes
Test your knowledge: Importance of threat and vulnerability management•8 minutes
Test your knowledge: Asset management•8 minutes
Test your knowledge: Vulnerability remediation and posture management•10 minutes
Test your knowledge: Patching and rehydration for system maintenance•10 minutes
Test your knowledge: Trends in threat management•10 minutes
1 app item•Total 90 minutes
Identify vulnerabilities and remediation techniques•90 minutes
Cloud Native Principles of Ephemerality and Immutability
Module 3•8 hours to complete
Module details
Ready to do some exploring? In this module, you'll discover cloud-native principles of ephemerality and immutability, focusing on proper credential handling that aligns with these concepts. You'll discover the automation of infrastructure provisioning and its impact on security, including key areas like containers, orchestration, and Infrastructure-as-Code (IaC).
What's included
14 videos13 readings6 assignments1 app item
Show info about module content
14 videos•Total 47 minutes
Welcome to module 3•1 minute
Cloud-native design and architecture principles•4 minutes
Cloud-native architecture for security•3 minutes
Introduction to ephemerality and immutability•4 minutes
Automation in cloud security•3 minutes
Infrastructure as code, policy as code, and DevSecOps•4 minutes
Benefits of policy as code•3 minutes
Terraform for IaC management•4 minutes
Containers vs. virtual machines•3 minutes
Container benefits and considerations•4 minutes
Techniques to secure containers•4 minutes
Container drift•4 minutes
Container orchestration•4 minutes
Wrap-up•1 minute
13 readings•Total 245 minutes
TTL policies and expiration•5 minutes
Automation to improve cloud security efficiency•20 minutes
AI and automation in security•20 minutes
Infrastructure as code and cloud-native security•20 minutes
Terraform and cloud security•20 minutes
Guide to automating deployment with Terraform•20 minutes
A brief guide to containers•20 minutes
Containers’ importance in the cloud•20 minutes
Security in containers•20 minutes
Serverless functions and security•20 minutes
Activity: Analyze the security of a container•30 minutes
Activity Exemplar: Analyze the security of a container•20 minutes
Glossary terms from module 3•10 minutes
6 assignments•Total 92 minutes
Module 3 challenge•50 minutes
Test your knowledge: Ephemerality and immutability•8 minutes
Test your knowledge: Automation in cloud infrastructure•8 minutes
Test your knowledge: Containers explained•8 minutes
Activity Quiz: Analyze the security of a container•8 minutes
Test your knowledge: Orchestrators and security of containers•10 minutes
1 app item•Total 90 minutes
Change firewall rules using Terraform and Cloud Shell•90 minutes
Data Protection and Privacy
Module 4•6 hours to complete
Module details
In this module, you'll gain a comprehensive understanding of data protection and privacy in the cloud. We’ll guide you through the essentials of data loss prevention, data discovery, data processing, data treatment, and data classification, empowering you to understand and implement effective data governance and access strategies. You'll also explore the nuances of data retention levels and how compliance controls are applied, so you can explain and navigate governance in cloud security.
What's included
14 videos10 readings5 assignments1 app item
Show info about module content
14 videos•Total 46 minutes
Welcome to module 4•1 minute
Introduction to the three states of data•2 minutes
Data encryption at rest, in transit, and in use•3 minutes
Data classification and tagging•4 minutes
Data governance for security and data quality•4 minutes
Data sovereignty and data governance•4 minutes
Data discovery to support data governance•3 minutes
Data retention policies•4 minutes
Create a business continuity plan•5 minutes
Business continuity scenario•2 minutes
Wrap-up•1 minute
Lauren: What makes candidates stand out•3 minutes
Patrick and Brenda: Interview role play•6 minutes
Course wrap-up•2 minutes
10 readings•Total 160 minutes
Data encryption•20 minutes
Asymmetric versus symmetric encryption•20 minutes
Protection of personally identifiable information (PII)•20 minutes
Cryptographic keys for data protection•20 minutes
Data sovereignty challenges and strategies•20 minutes
Plan for business continuity•20 minutes
Interview tip: Explain impact•10 minutes
Glossary terms from module 4•10 minutes
Course 3 resources and citations•10 minutes
Glossary terms from course 3•10 minutes
5 assignments•Total 86 minutes
Module 4 challenge•50 minutes
Test your knowledge: Cloud data protection and privacy techniques•8 minutes
Test your knowledge: Techniques for protection of personal data•10 minutes
Test your knowledge: Data sovereignty and data governance•10 minutes
Test your knowledge: Business continuity in cloud computing•8 minutes
1 app item•Total 90 minutes
Create symmetric and asymmetric keys•90 minutes
Earn a career certificate
Add this credential to your LinkedIn profile, resume, or CV. Share it on social media and in your performance review.
Instructor
Instructor ratings
Instructor ratings
We asked all learners to give feedback on our instructors based on the quality of their teaching style.
We help millions of organizations empower their employees, serve their customers, and build what’s next for their businesses with innovative technology created in—and for—the cloud. Our products are engineered for security, reliability, and scalability, running the full stack from infrastructure to applications to devices and hardware. Our teams are dedicated to helping customers apply our technologies to create success.
When will I have access to the lectures and assignments?
To access the course materials, assignments and to earn a Certificate, you will need to purchase the Certificate experience when you enroll in a course. You can try a Free Trial instead, or apply for Financial Aid. The course may offer 'Full Course, No Certificate' instead. This option lets you see all course materials, submit required assessments, and get a final grade. This also means that you will not be able to purchase a Certificate experience.
What will I get if I subscribe to this Certificate?
When you enroll in the course, you get access to all of the courses in the Certificate, and you earn a certificate when you complete the work. Your electronic Certificate will be added to your Accomplishments page - from there, you can print your Certificate or add it to your LinkedIn profile.