Google Cloud Digital LeaderSecurity and operations with Google CloudHard

A research institution is running computationally intensive simulations on Google Compute Engine. Due to the highly sensitive nature of the research data, they need to ensure that the data remains encrypted in memory during processing and is protected from underlying infrastructure attacks or malicious insiders with access to the hypervisor. Which Google Cloud feature provides this enhanced isolation and memory encryption?

  1. ACustomer-managed encryption keys (CMEK)
  2. BCloud Data Loss Prevention (DLP)
  3. CConfidential VMs
  4. DShielded VMs
Show answer & explanation

Correct answer: C. Confidential VMs

Confidential VMs leverage AMD SEV-ES technology to encrypt VM memory and isolate the guest VM from the host hypervisor, protecting data in use from cloud providers or malicious insiders.

Why the other options are wrong

  • A. CMEK encrypts data at rest, not in memory during processing.
  • B. Cloud DLP identifies and redacts sensitive data, primarily for data at rest or in transit, not for memory encryption during processing.
  • D. Shielded VMs provide integrity monitoring and verifiable boot, but not memory encryption for data in use.

Confidential VMs

Confidential VMs are a Google Compute Engine offering that keeps data encrypted in memory during processing, providing enhanced isolation from the cloud provider's infrastructure.

  • Encrypts VM memory with hardware-based keys.
  • Protects data in use from the hypervisor and host infrastructure.
  • Leverages AMD Secure Encrypted Virtualization - Encrypted State (SEV-ES).
  • Maintains data confidentiality even if the host is compromised.

Memory trick: Confidential VMs keep secrets even in RAM.

More Security and operations with Google Cloud questions