exam questions

Exam Professional Cloud DevOps Engineer All Questions

View all questions & answers for the Professional Cloud DevOps Engineer exam

Exam Professional Cloud DevOps Engineer topic 1 question 70 discussion

Actual exam question from Google's Professional Cloud DevOps Engineer
Question #: 70
Topic #: 1
[All Professional Cloud DevOps Engineer Questions]

You use Cloud Build to build and deploy your application. You want to securely incorporate database credentials and other application secrets into the build pipeline. You also want to minimize the development effort. What should you do?

  • A. Create a Cloud Storage bucket and use the built-in encryption at rest. Store the secrets in the bucket and grant Cloud Build access to the bucket.
  • B. Encrypt the secrets and store them in the application repository. Store a decryption key in a separate repository and grant Cloud Build access to the repository.
  • C. Use client-side encryption to encrypt the secrets and store them in a Cloud Storage bucket. Store a decryption key in the bucket and grant Cloud Build access to the bucket.
  • D. Use Cloud Key Management Service (Cloud KMS) to encrypt the secrets and include them in your Cloud Build deployment configuration. Grant Cloud Build access to the KeyRing.
Show Suggested Answer Hide Answer
Suggested Answer: D 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
TNT87
Highly Voted 2 years, 5 months ago
Ans is D
upvoted 16 times
...
jomonkp
Most Recent 4 months, 4 weeks ago
Selected Answer: D
option D
upvoted 1 times
...
maxdanny
5 months, 2 weeks ago
Selected Answer: D
https://cloud.google.com/build/docs/securing-builds/use-encrypted-credentials#configuring_builds_to_use_encrypted_data
upvoted 1 times
...
JonathanSJ
1 year, 3 months ago
Selected Answer: D
D. Use Cloud Key Management Service (Cloud KMS) to encrypt the secrets and include them in your Cloud Build deployment configuration. Grant Cloud Build access to the KeyRing. This option allows you to use Google-managed encryption and access controls, and it also minimizes the development effort required to securely incorporate the secrets into the build pipeline.
upvoted 1 times
...
zellck
1 year, 6 months ago
Selected Answer: D
D is the answer.
upvoted 2 times
...
ssmb
1 year, 6 months ago
Answer should be D in this case.
upvoted 2 times
...
FunkyB
1 year, 10 months ago
Ans: D Using encrypted credentials from Cloud KMS https://cloud.google.com/build/docs/securing-builds/use-encrypted-credentials
upvoted 2 times
...
emdee202
2 years ago
Selected Answer: D
Ans: D
upvoted 1 times
...
Sekierer
2 years, 3 months ago
D is correct
upvoted 2 times
...
Alaaelanwr
2 years, 6 months ago
Ans: D
upvoted 4 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago