Professional Cloud Security EngineerEnsuring complianceEasy

A healthcare organization is migrating patient data to Google Cloud. They require a robust internal Public Key Infrastructure (PKI) to issue and manage certificates for their internal applications, microservices, and IoT devices, ensuring strong authentication and encryption. They need a managed service that integrates well with Google Cloud and offers high availability. Which service should they choose?

  1. AIdentity Platform
  2. BSecret Manager
  3. CCloud Key Management Service (KMS)
  4. DCertificate Authority Service (CAS)
Show answer & explanation

Correct answer: D. Certificate Authority Service (CAS)

Certificate Authority Service (CAS) is a highly available, scalable Google Cloud service for managing and automating the deployment of private CAs, which is essential for issuing and managing internal certificates.

Why the other options are wrong

  • A. Identity Platform is for customer identity and access management, not for internal PKI.
  • B. Secret Manager stores secrets like API keys and passwords, not for operating a PKI.
  • C. Cloud KMS manages encryption keys, not the issuance and management of PKI certificates.

Certificate Authority Service (CAS)

A Google Cloud service that enables you to operate a highly available and scalable private certificate authority (CA) to issue and manage X.509 certificates.

  • Used for internal PKI for applications, microservices, and devices.
  • Managed service, reducing operational overhead.
  • Integrates with other Google Cloud services.

Memory trick: CAS issues certificates like a chief stamp officer.

More Ensuring compliance questions