Professional Cloud Security EngineerEnsuring data protectionEasy

A software development team uses Secret Manager to store database credentials and API keys. They need to ensure that these secrets are automatically rotated every 90 days to comply with security best practices, without manual intervention. How should they configure Secret Manager to meet this requirement?

  1. AImplement a Cloud Function triggered by a Pub/Sub topic to rotate secrets.
  2. BConfigure a rotation schedule directly in the Secret Manager UI or gcloud CLI.
  3. CSet an expiration date on the secret version and manually create a new version.
  4. DUse Cloud Scheduler to trigger a custom application that updates the secret.
Show answer & explanation

Correct answer: B. Configure a rotation schedule directly in the Secret Manager UI or gcloud CLI.

Secret Manager provides a built-in feature to configure an automatic rotation schedule for secrets. This allows you to specify a rotation period (e.g., 90 days) and a Cloud Function that will be invoked to perform the actual secret update, simplifying compliance with rotation policies.

Why the other options are wrong

  • A. While possible, Secret Manager offers a more integrated and simpler solution for this specific task.
  • C. Expiration dates do not trigger automatic rotation; they only mark a secret as expired.
  • D. Cloud Scheduler can trigger custom applications, but Secret Manager's integrated rotation feature is more direct and less complex for this specific use case.

Secret Manager Automatic Rotation

A feature in Google Cloud Secret Manager that automates the process of updating secret values at a specified interval.

  • Enhances security by regularly changing credentials.
  • Uses a Cloud Function for custom rotation logic.
  • Configurable via UI, gcloud CLI, or API.

Memory trick: Secrets rotate themselves, thanks to Secret Manager's built-in clock.

More Ensuring data protection questions