A financial institution is building a new application that processes highly sensitive transaction data. The application needs to run in a highly isolated and secure environment to protect against supply chain attacks and ensure the integrity of the runtime environment. They want to use a fully managed service that provides strong workload isolation and verifiable runtime integrity. Which Google Cloud service should they use?
- AGoogle Kubernetes Engine (GKE) with Shielded GKE Nodes
- BCloud Functions with VPC Service Controls
- CCloud Run with Binary Authorization
- DCompute Engine Confidential VMs
Show answer & explanationAnswer & explanation
Correct answer: D. Compute Engine Confidential VMs
Compute Engine Confidential VMs provide a breakthrough in cloud security by encrypting data in-use (in memory and CPU registers) with hardware-backed keys. This offers the highest level of isolation and protection against supply chain attacks and insider threats, ensuring verifiable runtime integrity, which is crucial for highly sensitive workloads like financial transactions.
Why the other options are wrong
- A. Shielded GKE Nodes provide enhanced security for GKE clusters, including verified boot, integrity monitoring, and vTPM. While strong, they do not encrypt data *in-use* in memory, which is a key feature of Confidential VMs for maximum isolation.
- B. Cloud Functions offer serverless execution for event-driven workloads. VPC Service Controls create security perimeters to prevent data exfiltration. Neither addresses the core requirement of strong workload isolation and verifiable runtime integrity at the hardware level during execution for highly sensitive data.
- C. Cloud Run is a fully managed serverless platform. Binary Authorization ensures only trusted container images are deployed. This addresses part of the supply chain security (trusted images) but doesn't provide the hardware-backed *runtime integrity* and *in-use encryption* that Confidential VMs offer.
Compute Engine Confidential VMs
Confidential VMs are a type of Compute Engine virtual machine that uses AMD Secure Encrypted Virtualization (SEV) to encrypt data *in-use* (in memory and CPU registers) with hardware-backed keys. This provides a strong isolation boundary, protecting data from unauthorized access even by cloud providers or other tenants.
- Encrypts data while it's being processed (in-use encryption)
- Uses hardware-backed keys (AMD SEV)
- Provides strong workload isolation and verifiable runtime integrity
- Protects against supply chain attacks and insider threats
- Ideal for highly sensitive data and regulated workloads
- Based on Compute Engine, so supports various machine types
Memory trick: Confidential VMs keep secrets even while they're thinking.