Google Cloud Digital LeaderSecurity and operations with Google CloudHard
A research institution is running computationally intensive simulations on Google Compute Engine (GCE) VMs. These simulations involve highly sensitive, proprietary algorithms and data that must remain confidential even from Google's infrastructure operators. The institution needs to ensure that the data and code are protected while in use (in memory and CPU registers). Which Google Cloud offering provides this 'confidential computing' capability?
- APreemptible VMs
- BShielded VMs
- CConfidential VMs
- DCustom Machine Types
Show answer & explanationAnswer & explanation
Correct answer: C. Confidential VMs
Confidential VMs leverage hardware-based encryption in memory and CPU to protect data in use, making it inaccessible to Google or other tenants, which is essential for highly sensitive workloads requiring 'confidential computing'.
Why the other options are wrong
- A. Preemptible VMs are cost-effective but short-lived VMs, not designed for enhanced security or confidentiality of data in use.
- B. Shielded VMs enhance VM security against rootkits and boot-level malware, but do not protect data in memory from the cloud provider.
- D. Custom Machine Types allow users to specify CPU and memory, but don't provide confidential computing features.
Confidential VMs
Confidential VMs are Google Compute Engine virtual machines that leverage hardware-based Confidential Computing technology to encrypt data in use (in memory and CPU).
- Protects data and code confidentiality while in use.
- Leverages AMD SEV (Secure Encrypted Virtualization) technology.
- Ensures data is encrypted in memory and inaccessible to the hypervisor or cloud operator.
- Maintains confidentiality for highly sensitive workloads.
Memory trick: Confidential VMs keep your secrets safe, even from the cloud itself.