Professional Cloud Security EngineerEnsuring complianceMedium
A media company is building a new content delivery platform on Google Cloud. They need to issue TLS certificates for thousands of internal microservices and external-facing APIs. They require a highly available, scalable, and secure service that integrates seamlessly with Google Cloud's infrastructure, allowing them to manage the entire certificate lifecycle without operating their own certificate authority (CA) infrastructure. Which Google Cloud service should they use?
- ACloud Key Management Service (KMS)
- BIdentity Platform
- CSecret Manager
- DCertificate Authority Service (CAS)
Show answer & explanationAnswer & explanation
Correct answer: D. Certificate Authority Service (CAS)
Certificate Authority Service (CAS) is a highly available and scalable Google Cloud service that allows organizations to operate their own private CAs to issue and manage X.509 certificates for internal and external use, without the operational overhead of managing physical CA infrastructure. This directly addresses the need for issuing and managing thousands of certificates for microservices and APIs.
Why the other options are wrong
- A. Cloud KMS manages cryptographic keys but does not issue or manage certificates.
- B. Identity Platform provides identity and access management for customer-facing applications, not certificate issuance.
- C. Secret Manager stores sensitive data like API keys and passwords, but does not issue certificates.
Certificate Authority Service (CAS)
A highly available and scalable Google Cloud service for managing private Certificate Authorities (CAs) and issuing X.509 certificates to secure internal services and external applications.
- Operates private CAs without infrastructure management.
- Integrates with other Google Cloud services (e.g., GKE, Load Balancers).
- Supports certificate lifecycle management (issuance, revocation, renewal).
Memory trick: CAS: Your Cloud Certificate Factory.