Professional Cloud Security EngineerEnsuring complianceEasy
A healthcare organization is migrating patient data to Google Cloud. They require a robust internal Public Key Infrastructure (PKI) to issue and manage certificates for their internal applications, microservices, and IoT devices, ensuring strong authentication and encryption. They need a managed service that integrates well with Google Cloud and offers high availability. Which service should they choose?
- AIdentity Platform
- BSecret Manager
- CCloud Key Management Service (KMS)
- DCertificate Authority Service (CAS)
Show answer & explanationAnswer & explanation
Correct answer: D. Certificate Authority Service (CAS)
Certificate Authority Service (CAS) is a highly available, scalable Google Cloud service for managing and automating the deployment of private CAs, which is essential for issuing and managing internal certificates.
Why the other options are wrong
- A. Identity Platform is for customer identity and access management, not for internal PKI.
- B. Secret Manager stores secrets like API keys and passwords, not for operating a PKI.
- C. Cloud KMS manages encryption keys, not the issuance and management of PKI certificates.
Certificate Authority Service (CAS)
A Google Cloud service that enables you to operate a highly available and scalable private certificate authority (CA) to issue and manage X.509 certificates.
- Used for internal PKI for applications, microservices, and devices.
- Managed service, reducing operational overhead.
- Integrates with other Google Cloud services.
Memory trick: CAS issues certificates like a chief stamp officer.