Google Associate Cloud EngineerEnsuring successful operation of a cloud solutionMedium

A developer is writing an application that needs to securely store sensitive configuration data, such as API keys and database credentials, and access them programmatically from Compute Engine instances. The solution must provide strong encryption, versioning, and access control. Which Google Cloud service should be used?

  1. ACloud Storage
  2. BCloud SQL
  3. CCloud KMS
  4. DSecret Manager
Show answer & explanation

Correct answer: D. Secret Manager

Secret Manager is a fully managed service for securely storing, managing, and accessing sensitive data like API keys, passwords, and certificates. It provides robust encryption, automatic versioning, and fine-grained access control, making it ideal for application secrets.

Why the other options are wrong

  • A. Cloud Storage is object storage, not designed for secret management, and while objects can be encrypted, it lacks the specific features like versioning of secrets and fine-grained access control for programmatic secret access.
  • B. Cloud SQL is a relational database service, not a secret management service. Storing credentials directly in a database is generally not a recommended security practice for application secrets.
  • C. Cloud KMS (Key Management Service) manages encryption keys but does not directly store the secrets themselves. It's used by services like Secret Manager for encryption, but it's not the primary service for storing the configuration data.

Secret Manager

A fully managed Google Cloud service for securely storing, managing, and accessing secrets such as API keys, passwords, and certificates.

  • Stores secrets securely with strong encryption
  • Provides automatic versioning for secrets
  • Offers fine-grained access control (IAM)
  • Integrates with other Google Cloud services

Memory trick: Secret Manager is the vault for your app's hidden treasures.

More Ensuring successful operation of a cloud solution questions