Google Professional Cloud Security Engineer exam dumps

Google Professional Cloud Security Engineer practice question 308 of 501

Professional Cloud Security Engineer. Expert level, Google Cloud. Free question with the correct answer and a full explanation.

Google Professional Cloud Security Engineer Question 308

Select 3Google Cloud Platform

Your organization uses Google Cloud Secret Manager to manage sensitive credentials such as API keys and database passwords. You have been tasked with ensuring that only specific services and users have access to read secrets, while also maintaining an audit trail of secret usage. What steps should you take to achieve this?

  1. A

    Grant the Secret Manager Admin role to all users who need access to secrets.

  2. B

    Use IAM roles such as Secret Manager Secret Accessor to provide read access to specific users or services.

  3. C

    Enable Secret Manager audit logs in Cloud Audit Logs to track access to secrets.

  4. D

    Store secrets in plaintext files on Compute Engine instances for faster access.

  5. E

    Configure fine-grained IAM policies for individual secrets or secret versions.

Show answer and explanation

Correct answers: B, C, E

Explanation

To securely manage secrets in Google Cloud Secret Manager, you should follow the principle of least privilege by assigning the Secret Accessor role only to authorized users or services. Additionally, enabling Cloud Audit Logs ensures that all secret access is tracked for auditing purposes. Fine-grained IAM policies allow you to further restrict access to specific secrets or versions, ensuring a robust and secure setup.

  • A. Incorrect.

    Granting the Secret Manager Admin role to all users is not a security best practice as it provides overly broad permissions, including the ability to manage and delete secrets.

  • B. Correct.

    Using the Secret Manager Secret Accessor role is the recommended way to provide read-only access to specific users or services, ensuring the principle of least privilege.

  • C. Correct.

    Enabling audit logs in Cloud Audit Logs ensures you have visibility into who accessed secrets and when, which is critical for maintaining an audit trail.

  • D. Incorrect.

    Storing secrets in plaintext files on Compute Engine instances is insecure and not recommended because it exposes sensitive credentials to unauthorized access.

  • E. Correct.

    Configuring fine-grained IAM policies for individual secrets or secret versions allows precise control over who can access specific secrets, enhancing security.

Timed practice exam

Take a Google Professional Cloud Security Engineer practice test under exam conditions

60 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam