More Info:

Ensure that GCP Cloud Monitoring mask the headers of HTTPS requests while checking backend resources health.

Risk Level

Medium

Address

Security

Compliance Standards

CBP

Triage and Remediation

Remediation

To remediate the misconfiguration “Cloud Monitoring Should Mask Headers For HTTPS Requests” for GCP using GCP console, you can follow the below steps:

  1. Open the GCP console and navigate to the Cloud Monitoring page.

  2. Click on the “Uptime Checks” option on the left-hand side menu.

  3. Select the HTTPS uptime check for which you want to mask headers.

  4. Click on the “Edit” button to edit the uptime check.

  5. Under the “Request” section, click on the “Add Header” button to add a new header.

  6. Enter the header name as “X-Goog-Monitoring-Mask-Headers” and the header value as a comma-separated list of headers that you want to mask.

  7. Save the changes by clicking on the “Save” button.

  8. Verify that the headers are masked by checking the monitoring logs.

By following the above steps, you can remediate the misconfiguration “Cloud Monitoring Should Mask Headers For HTTPS Requests” for GCP using GCP console.

Additional Reading: