Professional Cloud Security EngineerEnsuring complianceEasy
A defense contractor is deploying a highly secure application to Google Kubernetes Engine (GKE). They have a requirement that all sensitive configuration data, such as API keys and database credentials, must be stored and accessed in a manner that provides strong encryption, fine-grained access control, and a full audit trail of all access attempts. Which Google Cloud service is best suited for managing this sensitive data?
- AConfig Connector
- BSecret Manager
- CCloud SQL
- DCloud Storage
Show answer & explanationAnswer & explanation
Correct answer: B. Secret Manager
Secret Manager is a dedicated service for storing, managing, and accessing sensitive data (secrets) like API keys, passwords, and certificates. It offers strong encryption, fine-grained access control with IAM, automatic versioning, and detailed audit logging, making it ideal for secure configuration management in applications.
Why the other options are wrong
- A. Config Connector manages Google Cloud resources using Kubernetes APIs, but doesn't provide the underlying secret management functionality.
- C. Cloud SQL is a relational database service, not designed for general secret management.
- D. Cloud Storage is for object storage, not optimized for managing small, frequently accessed, highly sensitive secrets with versioning and audit trails.
Secret Manager
A Google Cloud service for securely storing, managing, and accessing sensitive data (secrets) such as API keys, passwords, and certificates.
- Offers strong encryption at rest and in transit.
- Provides fine-grained access control via IAM.
- Includes automatic versioning and detailed audit logging.
Memory trick: Secret Manager is the 'Vault' for your application's most sensitive keys and passwords.