Search icon
Arrow left icon
All Products
Best Sellers
New Releases
Books
Videos
Audiobooks
Learning Hub
Newsletters
Free Learning
Arrow right icon
Google Cloud Certified Professional Cloud Developer Exam Guide

You're reading from  Google Cloud Certified Professional Cloud Developer Exam Guide

Product type Book
Published in Sep 2021
Publisher Packt
ISBN-13 9781800560994
Pages 382 pages
Edition 1st Edition
Languages
Author (1):
Sebastian Moreno Sebastian Moreno
Profile icon Sebastian Moreno

Table of Contents (21) Chapters

Preface 1. Section 1: Welcome to the Google Cloud Developers' Guide
2. Chapter 1: Google Cloud Platform Developer Fundamentals 3. Chapter 2: Security Fundamentals and Best Practices 4. Section 2: Developing and Modernizing Applications on Google Cloud Platform
5. Chapter 3: Application Modernization Using Google Cloud 6. Chapter 4: Using Cloud Functions and Google App Engine 7. Chapter 5: Virtual Machines and Container Applications on Google Cloud Platform 8. Chapter 6: Managing APIs on Google Cloud Platform 9. Section 3: Storage Foundations
10. Chapter 7: Handling Unstructured Data 11. Chapter 8: Databases and Event Messages in Google Cloud 12. Chapter 9: Data Management and Database Strategies 13. Chapter 10: Optimizing Applications with Caching Strategies on Google Cloud Platform 14. Section 4: SRE for Developers
15. Chapter 11: Logging on Google Cloud Platform 16. Chapter 12: Cloud Monitoring, Tracing, and Debugging 17. Section 5: Analyzing a Sample Case Study
18. Chapter 13: HipLocal Sample Case Study Preparation 19. Chapter 14: Questions and Answers 20. Other Books You May Enjoy

Reducing the attack surface with POLP

Often, we find ourselves in a situation where, to speed up the development of our application, we grant permissions without understanding what we are really doing, just to make the code work. The problem with this strategy is that by assigning more permissions than the application needs to perform its functions, we increase its attack surface. This increases the possibility of vulnerabilities arising in our application, with the risk that these will be exploited by malicious actors. This is why POLP exists, and we will look at this in detail next.

POLP

The idea behind POLP is that each application must have the minimum permissions it needs in order to operate, so as to prevent an application from performing actions for which it was not created.

In order to comply with this principle, it is necessary to identify in the application design phase the dependencies of the services to be consumed and the actions that they will perform on these...

lock icon The rest of the chapter is locked
Register for a free Packt account to unlock a world of extra content!
A free Packt account unlocks extra newsletters, articles, discounted offers, and much more. Start advancing your knowledge today.
Unlock this book and the full library FREE for 7 days
Get unlimited access to 7000+ expert-authored eBooks and videos courses covering every tech area you can think of
Renews at $15.99/month. Cancel anytime}