GCP Professional Cloud Security Engineer Practice Question

Your organization's Cloud Build service account needs to retrieve a database password that is stored in a single Secret Manager secret. Compliance rules require that the service account be able to read only the secret's payload at deployment time; it must not be able to add new versions, change IAM policies, or list any other secrets in the project. Which single IAM role should you grant on that secret only to adhere to the principle of least privilege?

  • Grant the Secret Manager Admin role (roles/secretmanager.admin) on the specific secret.

  • Grant the Secret Manager Secret Version Manager role (roles/secretmanager.secretVersionManager) on the specific secret.

  • Grant the Secret Manager Viewer role (roles/secretmanager.viewer) on the project.

  • Grant the Secret Manager Secret Accessor role (roles/secretmanager.secretAccessor) on the specific secret.

GCP Professional Cloud Security Engineer
Ensuring data protection
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot