Lab 02 — Google Cloud Identity & Infrastructure Assessment
Welcome
Section titled “Welcome”Welcome to your first enterprise-style Google Cloud security assessment.
In this lab, you will move beyond building cloud infrastructure and begin thinking like a professional Cloud Penetration Tester.
Rather than deploying resources, your objective is to review an existing Google Cloud environment, identify security weaknesses, assess business risk, and document findings just as you would during a real consulting engagement.
This lab focuses on the three most important components of any Google Cloud environment:
- Identity & Access Management (IAM)
- Virtual Private Cloud (VPC)
- Compute Engine
By the end of this lab, you will have completed your first professional cloud infrastructure security assessment.
Mission Information
Section titled “Mission Information”| Item | Details |
|---|---|
| Difficulty | Intermediate |
| Duration | 90–120 Minutes |
| Lab Type | Enterprise Security Assessment |
| Platform | Google Cloud Platform |
| Career Track | Cloud Penetration Tester |
| Assessment Areas | IAM, Networking, Compute Engine |
| Methodology | GoHackersCloud Cloud Assessment Framework |
Learning Objectives
Section titled “Learning Objectives”After completing this lab, you will be able to:
- Assess Google Cloud IAM
- Review Service Accounts
- Evaluate IAM Roles
- Review VPC Architecture
- Assess Firewall Rules
- Review Network Segmentation
- Assess Compute Engine Security
- Identify cloud infrastructure security risks
- Produce professional assessment documentation
Business Scenario
Section titled “Business Scenario”CloudNova Technologies has been engaged to perform a security assessment for a rapidly growing software company that recently migrated its infrastructure to Google Cloud Platform.
The customer has requested an independent review of their cloud identity and infrastructure before onboarding additional production workloads.
Your objective is to identify security gaps that could increase organizational risk and provide practical recommendations for improvement.
Lab Scope
Section titled “Lab Scope”The assessment includes:
- Google Cloud IAM
- Users
- Groups
- Service Accounts
- IAM Roles
- Virtual Private Cloud (VPC)
- Firewall Rules
- Compute Engine
- Network Architecture
- Logging Configuration
Assessment Architecture
Section titled “Assessment Architecture” Google Cloud Project │ ┌───────────────┼───────────────┐ │ │ Google IAM VPC Network │ │ Users • Groups Firewall Rules Service Accounts │ │ │ └───────────────┬───────────────┘ │ Compute Engine │ Cloud LoggingLab Tasks
Section titled “Lab Tasks”Task 01 — Review Google Cloud IAM
Section titled “Task 01 — Review Google Cloud IAM”Objective
Section titled “Objective”Assess the organization’s identity and access management configuration.
Activities
Section titled “Activities”Review:
- Users
- Groups
- IAM Roles
- Custom Roles
- Project Permissions
- Organization Policies
Document:
- Administrative Accounts
- High-Privilege Users
- Overly Permissive Roles
Expected Outcome
Section titled “Expected Outcome”A complete understanding of the organization’s identity structure.
Task 02 — Assess Service Accounts
Section titled “Task 02 — Assess Service Accounts”Objective
Section titled “Objective”Review workload identities.
Activities
Section titled “Activities”Assess:
- Service Accounts
- Assigned Roles
- API Permissions
- Ownership
- Business Justification
- Unused Accounts
Document:
- High-Risk Service Accounts
- Excessive Permissions
- Missing Governance
Expected Outcome
Section titled “Expected Outcome”A Service Account assessment report.
Task 03 — Review Virtual Private Cloud (VPC)
Section titled “Task 03 — Review Virtual Private Cloud (VPC)”Objective
Section titled “Objective”Assess network architecture.
Activities
Section titled “Activities”Review:
- VPC Design
- Subnets
- Routes
- Private Networks
- Public Networks
- Shared VPC (if configured)
Create a simple network diagram.
Expected Outcome
Section titled “Expected Outcome”A documented enterprise network architecture.
Task 04 — Assess Firewall Rules
Section titled “Task 04 — Assess Firewall Rules”Objective
Section titled “Objective”Review network security controls.
Activities
Section titled “Activities”Review:
- Ingress Rules
- Egress Rules
- Allowed Ports
- Administrative Access
- Internet Exposure
- Rule Priorities
Identify:
- Overly Permissive Rules
- Unused Rules
- Misconfigurations
Expected Outcome
Section titled “Expected Outcome”Firewall assessment findings.
Task 05 — Review Compute Engine Security
Section titled “Task 05 — Review Compute Engine Security”Objective
Section titled “Objective”Assess virtual machine security.
Activities
Section titled “Activities”Review:
- Machine Configuration
- Operating System
- Metadata
- Service Account
- Shielded VM
- Boot Disk Encryption
- Public IP Addresses
- SSH Configuration
Document security observations.
Expected Outcome
Section titled “Expected Outcome”Compute Engine assessment report.
Task 06 — Review Logging & Monitoring
Section titled “Task 06 — Review Logging & Monitoring”Objective
Section titled “Objective”Verify infrastructure visibility.
Activities
Section titled “Activities”Review:
- Cloud Audit Logs
- Cloud Logging
- Monitoring
- Administrative Activity
- IAM Events
- Compute Logs
Verify that critical security events are recorded.
Expected Outcome
Section titled “Expected Outcome”Logging validation report.
Task 07 — Identify Security Findings
Section titled “Task 07 — Identify Security Findings”Review your assessment and classify findings.
Example categories include:
- Identity Risks
- Infrastructure Risks
- Network Risks
- Configuration Weaknesses
- Governance Issues
- Monitoring Gaps
Assign a severity to each finding.
| Severity | Description |
|---|---|
| Critical | Immediate business risk |
| High | Significant security weakness |
| Medium | Requires planned remediation |
| Low | Security improvement opportunity |
| Informational | Observation or best practice |
Task 08 — Produce an Assessment Report
Section titled “Task 08 — Produce an Assessment Report”Prepare a professional consulting report containing:
Executive Summary
Section titled “Executive Summary”- Overall security posture
- Key business risks
- High-level recommendations
Technical Findings
Section titled “Technical Findings”- IAM Review
- Service Account Review
- VPC Assessment
- Firewall Review
- Compute Engine Review
- Logging Review
Risk Register
Section titled “Risk Register”For each finding include:
- Description
- Business Impact
- Risk Rating
- Evidence
- Recommendation
- Remediation Priority
Validation Checklist
Section titled “Validation Checklist”Verify that you have completed the following:
- IAM Reviewed
- Service Accounts Assessed
- VPC Reviewed
- Firewall Rules Reviewed
- Compute Engine Assessed
- Logging Verified
- Security Findings Documented
- Executive Summary Prepared
- Technical Report Completed
Real-World Consultant Tips
Section titled “Real-World Consultant Tips”During enterprise cloud infrastructure assessments:
- Always understand the business context before reviewing technical controls.
- Validate the Principle of Least Privilege across all identities.
- Document every high-privilege account.
- Review internet-facing resources before internal systems.
- Verify that logging is enabled before making any changes.
- Support every finding with clear evidence.
- Prioritize recommendations based on business impact, not just technical severity.
Lab Deliverables
Section titled “Lab Deliverables”By the end of this lab, you should have:
- IAM Assessment Report
- Service Account Review
- Network Architecture Diagram
- Firewall Security Review
- Compute Engine Assessment
- Logging Validation Report
- Risk Register
- Executive Summary
- Technical Assessment Report
Skills You Will Gain
Section titled “Skills You Will Gain”After completing this lab, you will be able to:
- Perform enterprise Google Cloud infrastructure assessments.
- Evaluate IAM and identity governance.
- Review network security architecture.
- Assess Compute Engine deployments.
- Produce consulting-quality security reports.
- Prioritize risks based on business impact.
- Apply the GoHackersCloud Cloud Assessment Methodology.
Lab Summary
Section titled “Lab Summary”Congratulations!
You have completed your first enterprise Google Cloud Identity & Infrastructure Assessment.
This lab simulated a real consulting engagement where you reviewed identity management, network architecture, virtual machines, and monitoring controls to evaluate an organization’s security posture.
These same assessment techniques are used by Cloud Security Engineers and Cloud Penetration Testers when conducting enterprise cloud security reviews.
Next Lab
Section titled “Next Lab”➡️ Lab 03 — Google Cloud Data & Application Security Assessment
In the next lab, you will assess Google Cloud Storage, Cloud Functions, and Secret Manager, focusing on protecting enterprise data, securing serverless workloads, and validating application security controls.