Google PCA Manage and provision cloud infrastructure Practice Question
Which THREE are best practices for managing secrets (e.g., API keys, passwords) in Google Cloud? (Select exactly 3.)
⚠ Common exam trap
Google Cloud often tests the misconception that encrypting secrets before storing them in code repositories is acceptable, when in fact any storage in source control violates the principle of separation of secrets from code, and that environment variables are a secure method for passing secrets to Compute Engine instances, whereas they are easily exposed through metadata endpoints or process inspection.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Rotate secrets regularly and automatically where possible.
Regular, automated rotation of secrets limits the window of exposure if a secret is compromised. Secret Manager supports automatic rotation policies with a rotation period and next rotation time, and can trigger a Cloud Function or Cloud Run service to generate a new secret version, ensuring secrets are rotated without manual intervention.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Rotate secrets regularly and automatically where possible.
Why this is correct
Regular rotation reduces the risk of compromised secrets.
- ✗
Encrypt secrets and store them in source code repositories.
Why it's wrong here
Secrets should not be stored in source code, even encrypted, due to risk of exposure.
- ✓
Use Secret Manager to store and version secrets.
Why this is correct
Secret Manager is the recommended service for managing secrets securely.
- ✓
Grant access to secrets using IAM roles at the project or secret level.
Why this is correct
IAM provides fine-grained access control to secrets.
- ✗
Pass secrets as environment variables to Compute Engine instances.
Why it's wrong here
Environment variables can be visible in logs and process listings; use Secret Manager instead.
Go deeper
Related to this question
Learn chapter
Deployment Manager and Infrastructure as Code
Key term
Service
A service is a software component or system that performs a specific function and is available to be used by other programs or users over a network.
Key term
Secret Manager
A Secret Manager is a centralized tool that securely stores, manages, and controls access to sensitive information like passwords, API keys, and certificates, often automating their rotation and injection into applications.
About these practice questions
This PCA question is part of Courseiva's 807-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PCA practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCA exam.