Google PCA Design and plan a cloud solution architecture Practice Question
A retail company runs a Java-based order service on Compute Engine. The service currently reads its database credentials from a plaintext file on the boot disk. A security review requires that the credentials be removed from disk, be automatically rotated every 30 days, and be retrievable by the application through a single API call. You want the least operational overhead. What should you do?
⚠ Common exam trap
The trap here is assuming that encrypting a credential with Cloud KMS satisfies a requirement to remove it from disk and rotate it, when KMS rotates the wrapping key rather than the credential itself.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Store the credential as a version in Secret Manager, grant the VM's service account roles/secretmanager.secretAccessor on that secret, and configure a rotation schedule that publishes to a Pub/Sub topic.
The requirements point to a managed secret store with per-secret IAM and built-in rotation. Secret Manager keeps the credential off disk, lets the application retrieve it with one API call, and supports a rotation schedule that notifies a Pub/Sub topic so an automated workflow can update the underlying database password. Object storage, metadata, and KMS-wrapped files all leave the credential materialized on the instance or require custom rotation logic.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Encrypt the credentials file with a Cloud KMS key, keep it on the boot disk, and grant the VM's service account roles/cloudkms.cryptoKeyDecrypter so the application can decrypt it at startup.
Why it's wrong here
Cloud KMS protects data at rest and gives you strong key management, but the decrypted credential still lands on the boot disk, so the review's core requirement is unmet. KMS key rotation rotates the wrapping key, not the database password, so the 30-day credential rotation requirement is also not satisfied. This adds moving parts without solving the problem.
- ✗
Store the credentials in a Cloud Storage bucket with uniform bucket-level access and grant the VM's service account roles/storage.objectViewer, then have the application download the file at startup.
Why it's wrong here
Cloud Storage can hold the secret and IAM can restrict who reads it, but nothing in this design rotates the credential every 30 days. You would have to build and schedule your own rotation job, and the credential would still be materialized on the boot disk after download, which the review explicitly forbids. It also adds an object-read dependency rather than a purpose-built secret API.
- ✗
Store the credential in a custom metadata key on the instance and grant the VM's service account the compute.instanceAdmin.v1 role so it can read its own metadata.
Why it's wrong here
Instance metadata is readable by any process on the VM through the metadata server, so the credential is exposed to the whole workload and is not encrypted with a separate key. Granting compute.instanceAdmin.v1 is also far broader than needed and would let the workload modify or delete its own instance. No rotation mechanism is provided.
- ✓
Store the credential as a version in Secret Manager, grant the VM's service account roles/secretmanager.secretAccessor on that secret, and configure a rotation schedule that publishes to a Pub/Sub topic.
Why this is correct
Secret Manager is the managed service for this exact requirement: the secret never needs to live on disk, access is granted per-secret through IAM to the VM's attached service account, and a rotation schedule with a Pub/Sub notification lets a Cloud Function rotate the database password automatically. The application fetches the current version through one API call.
Go deeper
Related to this question
Learn chapter
Cloud SQL and Managed Data Stores
Key term
Pub/Sub
Pub/Sub is a messaging pattern where publishers send messages without knowing who receives them, and subscribers receive only the messages they care about.
Key term
CAN
A CAN (Controller Area Network) is a robust vehicle bus standard designed to allow microcontrollers and devices to communicate with each other without a host computer.
About these practice questions
One of 807 original PCA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Google Cloud exam blueprint
This PCA practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCA exam.