Professional Cloud Security EngineerEnsuring complianceMedium
A company is using Google Cloud for its customer-facing applications and wants to ensure that all SSL/TLS certificates for its external load balancers are managed securely and automatically renewed. They need a solution that minimizes manual intervention and integrates seamlessly with Google Cloud's networking services. Which service combination provides the best solution?
- ACertificate Authority Service (CAS) for issuing public certificates and Cloud Load Balancing.
- BCloud KMS for key storage and manual certificate rotation.
- CSecret Manager for certificate storage and custom scripts for renewal.
- DGoogle-managed SSL certificates with Cloud Load Balancing.
Show answer & explanationAnswer & explanation
Correct answer: D. Google-managed SSL certificates with Cloud Load Balancing.
Google-managed SSL certificates, integrated directly with Cloud Load Balancing, automatically provision, renew, and manage public SSL/TLS certificates, significantly reducing operational overhead and ensuring secure, up-to-date encryption for external traffic.
Why the other options are wrong
- A. CAS is for *private* CAs and certificates, not for public, internet-facing SSL/TLS certificates that need to be trusted by web browsers.
- B. Cloud KMS is for encryption key management, not for automated public certificate issuance and renewal, and manual rotation is inefficient.
- C. Secret Manager can store certificates, but it doesn't provide automated issuance or renewal for public trust, requiring complex custom scripting.
Google-managed SSL Certificates
A feature within Google Cloud Load Balancing that automatically provisions and renews public SSL/TLS certificates for external-facing applications.
- Handles certificate lifecycle (provisioning, renewal, revocation).
- Free of charge and integrates seamlessly with Cloud Load Balancing.
- Eliminates the need for manual certificate management.
Memory trick: Google-managed SSL is like a self-driving car for your certificates.