Intrigued by the art of cloud architecture? Discover how to design, develop, and manage robust, secure, scalable, and dynamic solutions on Google Cloud as you prepare for the Professional Cloud Architect exam!
Prepare and test your skills
Prepare and test your skills
Worked example. The correct answer is already marked and every option is explained below, so there is nothing to select here. To answer questions yourself, start the free trial.
An enterprise is designing an automated CI/CD pipeline on Google Cloud to deploy containerized workloads to Google Kubernetes Engine (GKE). The security team requires strict software supply chain controls and compliance enforcement across the SDLC:
Which combination of Google Cloud services and controls should the enterprise implement?
This architecture establishes an end-to-end secure software supply chain by integrating Secret Manager, automated vulnerability scanning (Artifact Analysis / Artifact Registry), and Binary Authorization into an automated CI/CD delivery pipeline.
This combination follows Google Cloud security best practices for supply chain integrity (SLSA framework alignment) by embedding preventive security controls directly into the deployment pipeline.
Keep the momentum going with these hand-picked practice scenarios
Want more questions like this?
Get a free certification question every week.