Google Cloud Certified - Professional Cloud DevOps Engineer Exam Professional-Cloud-DevOps-Engineer Question # 7 Topic 1 Discussion

Google Cloud Certified - Professional Cloud DevOps Engineer Exam Professional-Cloud-DevOps-Engineer Question # 7 Topic 1 Discussion

Professional-Cloud-DevOps-Engineer Exam Topic 1 Question 7 Discussion:
Question #: 7
Topic #: 1

Your application artifacts are being built and deployed via a CI/CD pipeline. You want the CI/CD pipeline to securely access application secrets. You also want to more easily rotate secrets in case of a security breach. What should you do?


A.

Prompt developers for secrets at build time. Instruct developers to not store secrets at rest.


B.

Store secrets in a separate configuration file on Git. Provide select developers with access to the configuration file.


C.

Store secrets in Cloud Storage encrypted with a key from Cloud KMS. Provide the CI/CD pipeline with access to Cloud KMS via IAM.


D.

Encrypt the secrets and store them in the source code repository. Store a decryption key in a separate repository and grant your pipeline access to it


Get Premium Professional-Cloud-DevOps-Engineer Questions

Contribute your Thoughts:


Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.