Intrigued by the art of cloud architecture? Discover how to design, develop, and manage robust, secure, scalable, and dynamic solutions on Google Cloud as you prepare for the Professional Cloud Architect exam!
Prepare and test your skills
Prepare and test your skills
Worked example. The correct answer is already marked and every option is explained below, so there is nothing to select here. To answer questions yourself, start the free trial.
Keep the momentum going with these hand-picked practice scenarios
Want more questions like this?
Get a free certification question every week.
Last updated
An enterprise organization is designing an automated CI/CD pipeline in Google Cloud to build and manage container images across staging and production environments. The cloud architecture and security teams have established the following requirements:
Which solution should the cloud architect implement?
Configure Cloud Deploy to compile application source code and generate containers, push built artifacts to an Artifact Registry remote repository pointing to Docker Hub, and disable vulnerability scanning.
Generate long-lived JSON service account keys, store them in the source Git repository, execute builds using local Docker daemons, and push images to Google Cloud Storage buckets.
Configure Cloud Build triggers with user-specified service accounts granted scoped IAM roles, define parameterized substitutions in cloudbuild.yaml, push images to Artifact Registry, and enable Artifact Analysis for vulnerability scanning and build provenance.
Use the default Cloud Build service account with Project Editor permissions, create environment-specific static cloudbuild.yaml files, push images to Artifact Registry, and use Cloud Workstations to manually verify image digests.
Configure Cloud Deploy to compile application source code and generate containers, push built artifacts to an Artifact Registry remote repository pointing to Docker Hub, and disable vulnerability scanning.
Generate long-lived JSON service account keys, store them in the source Git repository, execute builds using local Docker daemons, and push images to Google Cloud Storage buckets.
Configure Cloud Build triggers with user-specified service accounts granted scoped IAM roles, define parameterized substitutions in cloudbuild.yaml, push images to Artifact Registry, and enable Artifact Analysis for vulnerability scanning and build provenance.
This architecture leverages Google Cloud Build triggers configured with dedicated user-specified service accounts, parameterized build substitutions, and Google Cloud Artifact Registry integrated with Artifact Analysis for end-to-end supply chain security.
roles/artifactregistry.writer and roles/logging.logWriter), you prevent builds from executing with broad default project-level permissions.$PROJECT_ID) and user-defined substitutions (such as ${_LOCATION} and ${_REPOSITORY}) in a single cloudbuild.yaml allows the exact same build template to deploy across staging and production environments dynamically.Native integration between Cloud Build, Artifact Registry, and Artifact Analysis provides fully managed, serverless, and hardened CI/CD execution without needing third-party plugins or managing underlying build runner infrastructure.
Use the default Cloud Build service account with Project Editor permissions, create environment-specific static cloudbuild.yaml files, push images to Artifact Registry, and use Cloud Workstations to manually verify image digests.