Google Cloud Associate Cloud Engineer · Free practice question 12 of 12
Secret Manager for application credentials
A Cloud Run service at Oakhurst Ticketing needs a third-party API token. Today the token is hard-coded in the source repository. The team wants it stored centrally, versioned and readable only by the service's identity. What should they use?
- A.A label on the Cloud Run service containing the token
- B.Secret Manager, granting the service's service account the Secret Manager Secret Accessor role on the secret
- C.A Cloud Storage object with public read access
- D.A plain environment variable set in the Dockerfile
Show answer and explanation
Correct answer: B. Secret Manager, granting the service's service account the Secret Manager Secret Accessor role on the secret
Why: Secret Manager stores secrets with versioning and audit logging, and granting Secret Accessor only to the service account limits who can read the value; Cloud Run can expose a secret as an environment variable or volume. Values in a Dockerfile end up in the image and repository, public objects are readable by anyone, and labels are metadata visible to anyone who can view the service.
More free Google Cloud Associate Cloud Engineer questions
- Coldline minimum storage duration charge
- Cloud Run jobs for run-to-completion tasks
- Auto mode VPC creates regional subnets
- App Engine traffic splitting between versions
- gcloud config list active settings
- Globally unique Cloud Storage bucket names
- bq load CSV into a table
- kubectl rollout undo for bad releases
- Browser role for hierarchy visibility
- Log Analytics SQL queries on logs
- Cloud SQL Auth Proxy benefits