Skip to content

Lab 02 — Google Cloud Identity & Infrastructure Assessment

Welcome to your first enterprise-style Google Cloud security assessment.

In this lab, you will move beyond building cloud infrastructure and begin thinking like a professional Cloud Penetration Tester.

Rather than deploying resources, your objective is to review an existing Google Cloud environment, identify security weaknesses, assess business risk, and document findings just as you would during a real consulting engagement.

This lab focuses on the three most important components of any Google Cloud environment:

  • Identity & Access Management (IAM)
  • Virtual Private Cloud (VPC)
  • Compute Engine

By the end of this lab, you will have completed your first professional cloud infrastructure security assessment.


Item Details
Difficulty Intermediate
Duration 90–120 Minutes
Lab Type Enterprise Security Assessment
Platform Google Cloud Platform
Career Track Cloud Penetration Tester
Assessment Areas IAM, Networking, Compute Engine
Methodology GoHackersCloud Cloud Assessment Framework

After completing this lab, you will be able to:

  • Assess Google Cloud IAM
  • Review Service Accounts
  • Evaluate IAM Roles
  • Review VPC Architecture
  • Assess Firewall Rules
  • Review Network Segmentation
  • Assess Compute Engine Security
  • Identify cloud infrastructure security risks
  • Produce professional assessment documentation

CloudNova Technologies has been engaged to perform a security assessment for a rapidly growing software company that recently migrated its infrastructure to Google Cloud Platform.

The customer has requested an independent review of their cloud identity and infrastructure before onboarding additional production workloads.

Your objective is to identify security gaps that could increase organizational risk and provide practical recommendations for improvement.


The assessment includes:

  • Google Cloud IAM
  • Users
  • Groups
  • Service Accounts
  • IAM Roles
  • Virtual Private Cloud (VPC)
  • Firewall Rules
  • Compute Engine
  • Network Architecture
  • Logging Configuration

Google Cloud Project
┌───────────────┼───────────────┐
│ │
Google IAM VPC Network
│ │
Users • Groups Firewall Rules
Service Accounts │
│ │
└───────────────┬───────────────┘
Compute Engine
Cloud Logging

Assess the organization’s identity and access management configuration.

Review:

  • Users
  • Groups
  • IAM Roles
  • Custom Roles
  • Project Permissions
  • Organization Policies

Document:

  • Administrative Accounts
  • High-Privilege Users
  • Overly Permissive Roles

A complete understanding of the organization’s identity structure.


Review workload identities.

Assess:

  • Service Accounts
  • Assigned Roles
  • API Permissions
  • Ownership
  • Business Justification
  • Unused Accounts

Document:

  • High-Risk Service Accounts
  • Excessive Permissions
  • Missing Governance

A Service Account assessment report.


Task 03 — Review Virtual Private Cloud (VPC)

Section titled “Task 03 — Review Virtual Private Cloud (VPC)”

Assess network architecture.

Review:

  • VPC Design
  • Subnets
  • Routes
  • Private Networks
  • Public Networks
  • Shared VPC (if configured)

Create a simple network diagram.

A documented enterprise network architecture.


Review network security controls.

Review:

  • Ingress Rules
  • Egress Rules
  • Allowed Ports
  • Administrative Access
  • Internet Exposure
  • Rule Priorities

Identify:

  • Overly Permissive Rules
  • Unused Rules
  • Misconfigurations

Firewall assessment findings.


Task 05 — Review Compute Engine Security

Section titled “Task 05 — Review Compute Engine Security”

Assess virtual machine security.

Review:

  • Machine Configuration
  • Operating System
  • Metadata
  • Service Account
  • Shielded VM
  • Boot Disk Encryption
  • Public IP Addresses
  • SSH Configuration

Document security observations.

Compute Engine assessment report.


Verify infrastructure visibility.

Review:

  • Cloud Audit Logs
  • Cloud Logging
  • Monitoring
  • Administrative Activity
  • IAM Events
  • Compute Logs

Verify that critical security events are recorded.

Logging validation report.


Review your assessment and classify findings.

Example categories include:

  • Identity Risks
  • Infrastructure Risks
  • Network Risks
  • Configuration Weaknesses
  • Governance Issues
  • Monitoring Gaps

Assign a severity to each finding.

Severity Description
Critical Immediate business risk
High Significant security weakness
Medium Requires planned remediation
Low Security improvement opportunity
Informational Observation or best practice

Prepare a professional consulting report containing:

  • Overall security posture
  • Key business risks
  • High-level recommendations
  • IAM Review
  • Service Account Review
  • VPC Assessment
  • Firewall Review
  • Compute Engine Review
  • Logging Review

For each finding include:

  • Description
  • Business Impact
  • Risk Rating
  • Evidence
  • Recommendation
  • Remediation Priority

Verify that you have completed the following:

  • IAM Reviewed
  • Service Accounts Assessed
  • VPC Reviewed
  • Firewall Rules Reviewed
  • Compute Engine Assessed
  • Logging Verified
  • Security Findings Documented
  • Executive Summary Prepared
  • Technical Report Completed

During enterprise cloud infrastructure assessments:

  • Always understand the business context before reviewing technical controls.
  • Validate the Principle of Least Privilege across all identities.
  • Document every high-privilege account.
  • Review internet-facing resources before internal systems.
  • Verify that logging is enabled before making any changes.
  • Support every finding with clear evidence.
  • Prioritize recommendations based on business impact, not just technical severity.

By the end of this lab, you should have:

  • IAM Assessment Report
  • Service Account Review
  • Network Architecture Diagram
  • Firewall Security Review
  • Compute Engine Assessment
  • Logging Validation Report
  • Risk Register
  • Executive Summary
  • Technical Assessment Report

After completing this lab, you will be able to:

  • Perform enterprise Google Cloud infrastructure assessments.
  • Evaluate IAM and identity governance.
  • Review network security architecture.
  • Assess Compute Engine deployments.
  • Produce consulting-quality security reports.
  • Prioritize risks based on business impact.
  • Apply the GoHackersCloud Cloud Assessment Methodology.

Congratulations!

You have completed your first enterprise Google Cloud Identity & Infrastructure Assessment.

This lab simulated a real consulting engagement where you reviewed identity management, network architecture, virtual machines, and monitoring controls to evaluate an organization’s security posture.

These same assessment techniques are used by Cloud Security Engineers and Cloud Penetration Testers when conducting enterprise cloud security reviews.


➡️ Lab 03 — Google Cloud Data & Application Security Assessment

In the next lab, you will assess Google Cloud Storage, Cloud Functions, and Secret Manager, focusing on protecting enterprise data, securing serverless workloads, and validating application security controls.