Professional Cloud Security Engineer
Prepare and test your skills
Prepare and test your skills
Worked example. The correct answer is already marked and every option is explained below, so there is nothing to select here. To answer questions yourself, start the free trial.
Keep the momentum going with these hand-picked practice scenarios
Want more questions like this?
Get a free certification question every week.
Last updated
An enterprise organization stores database credentials in Google Cloud Secret Manager. The security team must implement continuous credential hygiene for these database secrets according to the following requirements:
Which workflow and architectural configuration should the security engineer implement?
Create a Cloud Scheduler job that runs every 30 days to invoke a Cloud Function over HTTP. Configure the Cloud Function to use the default Compute Engine service account to update the database, overwrite the existing secret payload using the Secret Manager REST API, and destroy the previous payload.
Set a 30-day expiration timestamp on the secret in Secret Manager. Configure a Cloud Storage object notification to trigger a Cloud Function that generates new credentials, stores them in a Cloud Storage bucket, and increments the secret version counter.
Configure an Eventarc trigger listening for Secret Manager audit log events in Cloud Logging. Direct Eventarc to execute a Cloud Function that rotates the database password and triggers a Cloud Build pipeline to inject the cleartext password into application environment variables.
Configure a rotation schedule with a 30-day rotation period and a target Pub/Sub topic on the secret. Grant the Secret Manager Service Agent the Pub/Sub Publisher role on the topic. Deploy a Cloud Function subscribed to the Pub/Sub topic that generates the new credential, updates the database, adds the new version to Secret Manager, and disables the previous version.
Create a Cloud Scheduler job that runs every 30 days to invoke a Cloud Function over HTTP. Configure the Cloud Function to use the default Compute Engine service account to update the database, overwrite the existing secret payload using the Secret Manager REST API, and destroy the previous payload.
Set a 30-day expiration timestamp on the secret in Secret Manager. Configure a Cloud Storage object notification to trigger a Cloud Function that generates new credentials, stores them in a Cloud Storage bucket, and increments the secret version counter.
Configure an Eventarc trigger listening for Secret Manager audit log events in Cloud Logging. Direct Eventarc to execute a Cloud Function that rotates the database password and triggers a Cloud Build pipeline to inject the cleartext password into application environment variables.
Configure a rotation schedule with a 30-day rotation period and a target Pub/Sub topic on the secret. Grant the Secret Manager Service Agent the Pub/Sub Publisher role on the topic. Deploy a Cloud Function subscribed to the Pub/Sub topic that generates the new credential, updates the database, adds the new version to Secret Manager, and disables the previous version.
Secret Manager automated rotation is a native lifecycle management capability that automatically schedules credential updates and invokes custom automation routines via Cloud Pub/Sub and serverless compute like Cloud Functions or Cloud Run.
next-rotation-time and rotation-period=2592000s (30 days) on the Secret Manager resource instructs Google Cloud to automatically trigger rotation events at the specified interval.ROTATION) to the configured Pub/Sub topic whenever the rotation timer elapses.service-@gcp-sa-secretmanager.iam.gserviceaccount.com) is granted the roles/pubsub.publisher role strictly on the designated topic, adhering to least-privilege principles.secrets.addVersion), verifies application access, and sets the state of the older version to Disabled (secrets.versions.disable).roles/secretmanager.secretVersionManager.This architecture leverages the purpose-built Secret Manager rotation framework, ensuring dependable event dispatching, decoupled execution, and continuous credential hygiene without service interruption.