Professional Cloud DevOps Engineer
Prepare and test your skills
Prepare and test your skills
Worked example. The correct answer is already marked and every option is explained below, so there is nothing to select here. To answer questions yourself, start the free trial.
Keep the momentum going with these hand-picked practice scenarios
Want more questions like this?
Get a free certification question every week.
Last updated
Your team is establishing a "shift-left" security practice for containerized applications built with Cloud Build and stored in Artifact Registry. You need to implement an automated policy gate within the continuous integration (CI) pipeline that satisfies the following requirements:
CRITICAL or HIGH is detected.What should you do?
Incorporate On-Demand Scanning in Cloud Build by running gcloud artifacts docker images scan on the locally built image, then parse the results with gcloud artifacts docker images list-vulnerabilities and terminate the build step with an exit code of 1 if CRITICAL or HIGH severities are found before pushing.
Push the image to Artifact Registry and run gcloud artifacts docker images describe --show-package-vulnerability in a subsequent Cloud Build step to verify compliance before deploying.
Configure Binary Authorization admission rules in Cloud Build to evaluate container Dockerfile instructions and block the build if vulnerable base OS layers are detected.
Enable automatic vulnerability scanning in Artifact Registry, push the image, and configure a Cloud Function triggered by Pub/Sub notifications to delete the image if vulnerabilities are found.
Incorporate On-Demand Scanning in Cloud Build by running gcloud artifacts docker images scan on the locally built image, then parse the results with gcloud artifacts docker images list-vulnerabilities and terminate the build step with an exit code of 1 if CRITICAL or HIGH severities are found before pushing.
Artifact Analysis On-Demand Scanning is a feature that allows developers and CI/CD systems to initiate vulnerability scans on container images locally or during build time before pushing them to a central repository like Artifact Registry.
gcloud artifacts docker images scan analyzes the local container image built in the pipeline workspace prior to executing a docker push step.gcloud artifacts docker images list-vulnerabilities queries the scan ID and outputs metadata including the vulnerability.effectiveSeverity level.CRITICAL or HIGH. If found, it outputs a failure message and exits with a non-zero exit code (exit 1), halting the Cloud Build pipeline immediately and blocking subsequent steps (such as docker push).'CRITICAL|HIGH').On-Demand Scanning allows proactive evaluation of artifact compliance directly within the CI execution runner. Waiting until after the image is stored in the registry or deployed to a cluster increases the attack surface and requires reactive mitigation instead of preventative enforcement.
Push the image to Artifact Registry and run gcloud artifacts docker images describe --show-package-vulnerability in a subsequent Cloud Build step to verify compliance before deploying.
Configure Binary Authorization admission rules in Cloud Build to evaluate container Dockerfile instructions and block the build if vulnerable base OS layers are detected.
Enable automatic vulnerability scanning in Artifact Registry, push the image, and configure a Cloud Function triggered by Pub/Sub notifications to delete the image if vulnerabilities are found.