Professional Cloud DevOps Engineer
Prepare and test your skills
Prepare and test your skills
Worked example. The correct answer is already marked and every option is explained below, so there is nothing to select here. To answer questions yourself, start the free trial.
An enterprise is designing a secure software supply chain pipeline for containerized applications deployed to Google Kubernetes Engine (GKE). The security architecture must satisfy the following requirements:
Which combination of Google Cloud security controls and architectural practices should the DevOps engineer implement?
This architecture combines Artifact Registry Customer-Managed Encryption Keys (CMEK), VPC Service Controls (VPC SC) perimeters, and Binary Authorization on Google Kubernetes Engine (GKE) to establish an end-to-end secure software supply chain.
containersecurity.googleapis.com) services to a VPC Service Controls perimeter prevents data exfiltration and restricts unauthorized ingress/egress across project boundaries.This approach directly addresses storage encryption, network-level data exfiltration boundaries, and deploy-time admission enforcement natively within Google Cloud without requiring third-party runtime agents or unmanaged custom scripts.
Keep the momentum going with these hand-picked practice scenarios
Want more questions like this?
Get a free certification question every week.