Professional Cloud Security EngineerEnsuring complianceEasy

A defense contractor is deploying a highly secure application to Google Kubernetes Engine (GKE). They have a requirement that all sensitive configuration data, such as API keys and database credentials, must be stored and accessed in a manner that provides strong encryption, fine-grained access control, and a full audit trail of all access attempts. Which Google Cloud service is best suited for managing this sensitive data?

  1. AConfig Connector
  2. BSecret Manager
  3. CCloud SQL
  4. DCloud Storage
Show answer & explanation

Correct answer: B. Secret Manager

Secret Manager is a dedicated service for storing, managing, and accessing sensitive data (secrets) like API keys, passwords, and certificates. It offers strong encryption, fine-grained access control with IAM, automatic versioning, and detailed audit logging, making it ideal for secure configuration management in applications.

Why the other options are wrong

  • A. Config Connector manages Google Cloud resources using Kubernetes APIs, but doesn't provide the underlying secret management functionality.
  • C. Cloud SQL is a relational database service, not designed for general secret management.
  • D. Cloud Storage is for object storage, not optimized for managing small, frequently accessed, highly sensitive secrets with versioning and audit trails.

Secret Manager

A Google Cloud service for securely storing, managing, and accessing sensitive data (secrets) such as API keys, passwords, and certificates.

  • Offers strong encryption at rest and in transit.
  • Provides fine-grained access control via IAM.
  • Includes automatic versioning and detailed audit logging.

Memory trick: Secret Manager is the 'Vault' for your application's most sensitive keys and passwords.

More Ensuring compliance questions