Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Google Professional Cloud Security Engineer Exam - Topic 3 Question 118 Discussion

You are asked to recommend a solution to store and retrieve sensitive configuration data from an application that runs on Compute Engine. Which option should you recommend?
D) Secret Manager
A) Cloud Key Management Service
B) Compute Engine guest attributes
C) Compute Engine custom metadata

Google Professional Cloud Security Engineer Exam - Topic 3 Question 118 Discussion

Actual exam question for Google's Professional Cloud Security Engineer exam
Question #: 118
Topic #: 3
[All Professional Cloud Security Engineer Questions]

You are asked to recommend a solution to store and retrieve sensitive configuration data from an application that runs on Compute Engine. Which option should you recommend?

Show Suggested Answer Hide Answer
Suggested Answer: D

Objective: Store and retrieve sensitive configuration data for an application running on Compute Engine.

Solution: Use Secret Manager to securely store and manage access to sensitive configuration data.

Steps:

Step 1: Open the Google Cloud Console.

Step 2: Navigate to the Secret Manager section.

Step 3: Create a new secret and add the sensitive configuration data.

Step 4: Set appropriate IAM policies to control access to the secret.

Step 5: Update the application to retrieve the secret from Secret Manager using the appropriate client libraries or APIs.

Secret Manager provides a secure and centralized way to manage sensitive information, with fine-grained access control and audit logging capabilities.


Secret Manager Documentation

Storing and Accessing Secrets

Contribute your Thoughts:

0/2000 characters
Margurite
4 days ago
A) Cloud Key Management Service is also good, but not as focused.
upvoted 0 times
...
Kenneth
9 days ago
Agreed! It’s designed for sensitive data.
upvoted 0 times
...
Teddy
14 days ago
I think D) Secret Manager is the best choice.
upvoted 0 times
...
Anisha
19 days ago
I didn't know Secret Manager was that secure, sounds interesting!
upvoted 0 times
...
Aretha
24 days ago
B and C are not secure enough for sensitive info.
upvoted 0 times
...
Latonia
29 days ago
Wait, isn't A) Cloud Key Management Service also a good option?
upvoted 0 times
...
Herschel
1 month ago
Totally agree, Secret Manager is the best choice!
upvoted 0 times
...
Devon
1 month ago
I'd go with D) Secret Manager for sensitive data.
upvoted 0 times
...
Jacinta
1 month ago
I’m leaning towards Secret Manager, but I wonder if Compute Engine custom metadata could also be a viable option for some use cases.
upvoted 0 times
...
Rhea
2 months ago
I practiced a similar question where we had to choose between different storage options, and I think Cloud Key Management Service was mentioned as more for encryption keys rather than configuration data.
upvoted 0 times
...
Alva
2 months ago
I feel like we discussed Compute Engine guest attributes in class, but I can't recall if they're secure enough for sensitive data.
upvoted 0 times
...
Twila
2 months ago
I think I remember that Secret Manager is specifically designed for storing sensitive data, but I'm not entirely sure if it's the best option here.
upvoted 0 times
...

Save Cancel