Google Professional Cloud Security Engineer exam dumps

Google Professional Cloud Security Engineer practice question 307 of 501

Professional Cloud Security Engineer. Expert level, Google Cloud. Free question with the correct answer and a full explanation.

Google Professional Cloud Security Engineer Question 307

Select 3Google Cloud Platform

You are a Professional Cloud Security Engineer at a company that uses Google Cloud. The development team wants to securely store API keys and database credentials for their applications. They need to ensure that access to these secrets is tightly controlled, and they want to allow only specific service accounts to access the secrets. How can you achieve this using Google Cloud Secret Manager?

  1. A

    Store the API keys and database credentials in Secret Manager and use IAM policies to grant access only to the required service accounts.

  2. B

    Encrypt the secrets with a customer-managed encryption key (CMEK) in Secret Manager for additional security.

  3. C

    Configure Secret Manager to automatically rotate secrets on a predefined schedule.

  4. D

    Grant all users in the project Editor role to ensure they can manage secrets if needed.

  5. E

    Use the Secret Manager API to programmatically retrieve secrets from applications running on Google Cloud.

Show answer and explanation

Correct answers: A, B, E

Explanation

To securely store secrets with Secret Manager, you should use IAM policies to restrict access to only the required service accounts (least privilege principle). Additionally, enabling customer-managed encryption keys (CMEK) adds an extra layer of security by giving you control over encryption. The Secret Manager API allows seamless integration with applications to retrieve secrets securely. Avoid granting broad roles, like Editor, and ensure secret rotation is used as needed, but it is not strictly required for this scenario.

  • A. Correct.

    Correct: Secret Manager integrates with IAM, allowing you to define granular access controls. This ensures only the required service accounts can access the secrets while restricting others.

  • B. Correct.

    Correct: Using a customer-managed encryption key (CMEK) provides additional control over encryption, enhancing security for sensitive data stored in Secret Manager.

  • C. Incorrect.

    Incorrect: While automatic secret rotation is a good practice, it is not a required step to securely store and control access to secrets. It is optional and depends on the use case.

  • D. Incorrect.

    Incorrect: Granting the Editor role to all users in the project is overly permissive and violates the principle of least privilege. This could expose secrets to unauthorized users.

  • E. Correct.

    Correct: The Secret Manager API allows applications to programmatically access secrets, ensuring secure delivery of sensitive data to approved workloads.

Timed practice exam

Take a Google Professional Cloud Security Engineer practice test under exam conditions

60 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam