Google Cloud Digital LeaderSecurity and operations with Google CloudHard

A research institution is running computationally intensive simulations on Google Compute Engine VMs. They need to ensure that the data processed by these VMs remains confidential and is not accessible to the underlying cloud infrastructure or other tenants, even when the VMs are running. Which Google Cloud security technology provides this level of isolation and protection for data in use?

  1. ACustomer-Managed Encryption Keys (CMEK)
  2. BConfidential VMs
  3. CShielded VMs
  4. DVPC Service Controls
Show answer & explanation

Correct answer: B. Confidential VMs

Confidential VMs use AMD Secure Encrypted Virtualization (SEV) to encrypt VM memory and CPU registers with a dedicated, hardware-generated key, protecting data in use (at runtime) from the underlying cloud infrastructure and other tenants.

Why the other options are wrong

  • A. CMEK encrypts data at rest (stored data), not data actively being processed in memory or CPU.
  • C. Shielded VMs protect against rootkits and boot-level malware by verifying boot integrity, but do not encrypt data in use from the hypervisor.
  • D. VPC Service Controls prevent data exfiltration at the network perimeter, not protecting data in use within a VM.

Confidential VMs

Confidential VMs are a Google Cloud technology that encrypts data in use (data in memory and CPU registers) with a hardware-generated key, protecting it from the cloud provider and other tenants.

  • Uses AMD Secure Encrypted Virtualization (SEV).
  • Protects against unauthorized access to data while it's being processed.
  • Aims to achieve a 'zero-trust' security posture for data in use.

Memory trick: Confidential VMs Protect Data In Use.

More Security and operations with Google Cloud questions