
Google CloudProfessional Cloud DevOps Engineer
Domain 2Objective 3
2.3 Managing Pipeline Configuration and Secrets PROFESSIONAL-CLOUD-DEVOPS-ENGINEER Practice Questions (Page 2)
Part of the Section 2: Building and implementing CI/CD pipelines, including continuous testing, for application, infrastructure, and machine learning workloads domain, which accounts for ~25% of the exam of the PROFESSIONAL-CLOUD-DEVOPS-ENGINEER exam.
30questions here
6free pages
8concepts
~25% of the examof the exam
Questions 6–10
- 6
A Cloud Build pipeline needs to access a secret stored in Secret Manager during a build step. The engineer wants to ensure that the secret is not visible in the build logs. What should they do?
Select an answer first - 7
A DevOps engineer needs to grant a CI/CD service account permission to encrypt data with a specific Cloud KMS key. Which IAM role should be assigned at the key level?
Select an answer first - 8
A DevOps engineer is designing a pipeline for a microservices application. Some secrets are needed only during the build (e.g., API keys for pulling dependencies), while others are needed at runtime (e.g., database credentials). What is the best practice for handling these secrets?
Select an answer first - 9
A company is migrating to Google Cloud and needs to manage SSL/TLS certificates for multiple domains. They want to use a single certificate for multiple domains and have it automatically renewed. The certificate must be used by an HTTPS load balancer. What should the engineer do?
Select an answer first - 10
A security team requires that all secrets stored in Secret Manager be encrypted with a customer-managed key. The DevOps engineer needs to configure this. What should they do?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by Google Cloud. “PROFESSIONAL-CLOUD-DEVOPS-ENGINEER” is a trademark of its owner, used for identification only.