GCP Professional Cloud Security Engineer Practice Question
A financial services company subject to PCI DSS is adopting Google Secret Manager to store API keys used by a GKE-based microservice platform. Auditors require proof that
the keys are never transmitted in clear text across Google's network, and
encryption at rest uses at least 256-bit strength. Which statement accurately explains how Secret Manager meets these two requirements without any extra configuration by the platform team?
Secrets are protected in transit via TLS, but you must enable customer-managed encryption keys to ensure AES-256 encryption at rest.
Secret Manager automatically encrypts every secret with Google-managed AES-256 at rest and enforces TLS for all access requests, so both requirements are satisfied out of the box.
By default, Secret Manager uses AES-128 for storage; to reach 256-bit strength and ensure encrypted transport you must configure mutual TLS between clients and the service.
Secrets remain unencrypted on disk unless you configure a Cloud HSM-backed key; transport encryption is optional but recommended.
Secret Manager automatically encrypts every secret version at rest using Google-managed AES-256 keys. It also exposes its API only over HTTPS; all requests must be made through TLS-protected connections, and data is encrypted while in transit between clients and Google's service endpoints. Because both protections are enabled by default, no additional configuration-such as enabling CMEK, adding Cloud HSM, or configuring mutual TLS-is required to meet the auditors' requirements. The other options are incorrect because Secret Manager never stores plaintext, does not default to AES-128, and does not require CMEK or HSM to achieve AES-256 encryption or TLS in transit.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is AES-256 encryption and why is it used?
Open an interactive chat with Bash
How does TLS protect data in transit?
Open an interactive chat with Bash
What is the purpose of Google Secret Manager in a GKE environment?
Open an interactive chat with Bash
What is AES-256 encryption?
Open an interactive chat with Bash
How does TLS ensure secure data transmission?
Open an interactive chat with Bash
What is PCI DSS, and why is it important?
Open an interactive chat with Bash
GCP Professional Cloud Security Engineer
Ensuring data protection
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .