Professional Cloud DevOps Engineer
Prepare and test your skills
Prepare and test your skills
Worked example. The correct answer is already marked and every option is explained below, so there is nothing to select here. To answer questions yourself, start the free trial.
Keep the momentum going with these hand-picked practice scenarios
Want more questions like this?
Get a free certification question every week.
Last updated
Your team is building an automated incident triage service hosted outside Google Cloud that consumes alert notifications from Cloud Monitoring. The security team establishes the following technical requirements for the integration:
How should you configure the custom webhook notification channel in Cloud Monitoring and the receiving service?
Configure the notification channel with an HTTPS endpoint URL containing the shared secret as a query string parameter, and configure the receiving service to validate the token parameter against its stored secret.
Configure the notification channel using an asymmetric HMAC digital signature in the custom payload schema, and configure the receiving service to verify the signature header.
Configure the notification channel with HTTP Basic Authentication credentials, and configure the receiving service to accept the initial POST request without returning a 401 Unauthorized status code.
Configure the notification channel with an plain HTTP endpoint URL containing the shared secret as a query string parameter, and configure the receiving service to validate the token parameter against its stored secret.
Configure the notification channel with an HTTPS endpoint URL containing the shared secret as a query string parameter, and configure the receiving service to validate the token parameter against its stored secret.
Token-based authentication for Cloud Monitoring webhooks is a mechanism where a unique shared secret token is passed directly within the endpoint URL's query string (for example, https://monitoring-receiver.example.com/alerts?auth_token=SECRET_VALUE). When Cloud Monitoring triggers an alert notification, it issues an HTTP POST request to this target URL, allowing the external receiving service to extract and validate the token parameter before processing the incident payload.
auth_token), comparing the value against a securely stored secret key. If the token is missing or incorrect, the server rejects the request with an HTTP 401 Unauthorized or 403 Forbidden status code.This design directly fulfills all security and architectural constraints using native Cloud Monitoring webhook functionality. Combining query-based token authentication with TLS provides confidentiality and origin verification with minimal operational overhead.
Configure the notification channel using an asymmetric HMAC digital signature in the custom payload schema, and configure the receiving service to verify the signature header.
Configure the notification channel with HTTP Basic Authentication credentials, and configure the receiving service to accept the initial POST request without returning a 401 Unauthorized status code.
Configure the notification channel with an plain HTTP endpoint URL containing the shared secret as a query string parameter, and configure the receiving service to validate the token parameter against its stored secret.