Professional Cloud DevOps Engineer
Prepare and test your skills
Prepare and test your skills
Worked example. The correct answer is already marked and every option is explained below, so there is nothing to select here. To answer questions yourself, start the free trial.
Keep the momentum going with these hand-picked practice scenarios
Want more questions like this?
Get a free certification question every week.
Last updated
A DevOps team is developing a continuous integration and continuous delivery (CI/CD) pipeline using Cloud Build to automate project environment bootstrapping and resource configuration. The workflow must execute custom Python automation scripts that interact with Google Cloud APIs and configure external third-party services.
The pipeline implementation must satisfy the following criteria:
How should the team design the Cloud Build configuration and Python automation workflow?
Encrypt the credentials with a Cloud KMS symmetric key, commit the encrypted ciphertext string into the Git repository, and grant the Cloud Build service account Cloud KMS CryptoKey Encrypter/Decrypter permissions to decrypt the payload on workspace disk.
Upload a credentials JSON file to a private Cloud Storage bucket, grant the Cloud Build service account Storage Object Viewer permissions, and download the credentials file into the build workspace prior to executing Python scripts.
Store the credentials in Secret Manager, grant the Cloud Build service account the Secret Manager Secret Accessor role, reference the secret in the availableSecrets configuration block of cloudbuild.yaml to expose it securely via an environment variable, and access it in the Python script at execution time.
Define custom user substitution variables (e.g., _API_KEY) in the Cloud Build trigger definition, pass the plaintext credentials as build arguments to the Python step, and verify infrastructure health using inline shell assertions.
Encrypt the credentials with a Cloud KMS symmetric key, commit the encrypted ciphertext string into the Git repository, and grant the Cloud Build service account Cloud KMS CryptoKey Encrypter/Decrypter permissions to decrypt the payload on workspace disk.
Upload a credentials JSON file to a private Cloud Storage bucket, grant the Cloud Build service account Storage Object Viewer permissions, and download the credentials file into the build workspace prior to executing Python scripts.
Store the credentials in Secret Manager, grant the Cloud Build service account the Secret Manager Secret Accessor role, reference the secret in the availableSecrets configuration block of cloudbuild.yaml to expose it securely via an environment variable, and access it in the Python script at execution time.
Secret Manager is Google Cloud's fully managed service designed to store, manage, and access sensitive metadata and operational credentials. Integrating Secret Manager natively with Cloud Build allows build steps to inject secrets into memory as environment variables or retrieve them dynamically via API clients.
availableSecrets block ensures tokens are mounted directly into containerized build step environments rather than stored in cleartext source files or configuration manifests.roles/secretmanager.secretAccessor) role limits permissions to reading only the necessary secret payload without granting broader administrative rights.os.environ['SECRET_KEY']) or the Secret Manager client library to provision infrastructure, after which a secondary test step validates the environment.cloudbuild.yaml without needing custom decryption tooling.This approach aligns with Google Cloud security best practices by separating configuration from credentials, leveraging native service-level IAM controls, and preventing secret exposure across CI/CD log streams.
Define custom user substitution variables (e.g., _API_KEY) in the Cloud Build trigger definition, pass the plaintext credentials as build arguments to the Python step, and verify infrastructure health using inline shell assertions.