CertKeen

Google Cloud Associate Cloud Engineer · Free practice question 12 of 12

Secret Manager for application credentials

A Cloud Run service at Oakhurst Ticketing needs a third-party API token. Today the token is hard-coded in the source repository. The team wants it stored centrally, versioned and readable only by the service's identity. What should they use?

  1. A.A label on the Cloud Run service containing the token
  2. B.Secret Manager, granting the service's service account the Secret Manager Secret Accessor role on the secret
  3. C.A Cloud Storage object with public read access
  4. D.A plain environment variable set in the Dockerfile
Show answer and explanation

Correct answer: B. Secret Manager, granting the service's service account the Secret Manager Secret Accessor role on the secret

Why: Secret Manager stores secrets with versioning and audit logging, and granting Secret Accessor only to the service account limits who can read the value; Cloud Run can expose a secret as an environment variable or volume. Values in a Dockerfile end up in the image and repository, public objects are readable by anyone, and labels are metadata visible to anyone who can view the service.

More free Google Cloud Associate Cloud Engineer questions