Professional Cloud Security EngineerEnsuring complianceMedium

A global e-commerce company is expanding its operations and requires the ability to issue and manage its own private X.509 certificates for internal microservices, IoT devices, and mutual TLS authentication, ensuring high availability and compliance with industry standards. They need a managed service that can handle the entire lifecycle of these certificates. Which Google Cloud service should they use?

  1. ACertificate Authority Service (CAS)
  2. BLoad Balancing SSL certificates
  3. CSecret Manager
  4. DCloud Key Management Service (KMS)
Show answer & explanation

Correct answer: A. Certificate Authority Service (CAS)

Certificate Authority Service (CAS) is a highly available and scalable Google Cloud service that allows you to simplify the deployment, management, and security of private certificate authorities (CAs). It handles the full lifecycle of private X.509 certificates for various internal use cases.

Why the other options are wrong

  • B. Load Balancing SSL certificates manage publicly trusted certificates for external load balancers and do not provide a private CA for internal services.
  • C. Secret Manager stores and manages sensitive data like API keys and passwords, not certificate authorities.
  • D. Cloud KMS manages cryptographic keys, not the issuance or lifecycle of X.509 certificates.

Certificate Authority Service (CAS)

A Google Cloud managed service for deploying, managing, and securing private certificate authorities (CAs) to issue and revoke X.509 certificates.

  • Simplifies private certificate management at scale.
  • Supports various use cases like mTLS, IoT, code signing.
  • Offers high availability and integrates with other Google Cloud services.

Memory trick: CAS is your 'Digital Passport Office' in the cloud, issuing trusted IDs for your services.

More Ensuring compliance questions