Professional Cloud DevOps Engineer
Prepare and test your skills
Prepare and test your skills
Worked example. The correct answer is already marked and every option is explained below, so there is nothing to select here. To answer questions yourself, start the free trial.
Keep the momentum going with these hand-picked practice scenarios
Want more questions like this?
Get a free certification question every week.
Last updated
Your enterprise is deploying Google Cloud Workstations for a software development team requiring custom development tooling and internal security packages. You must establish a secure lifecycle and deployment workflow for these workstations that satisfies the following requirements:
Which combination of steps should you implement to satisfy these requirements?
Build custom container images manually using Docker on a local workstation, push the images to Artifact Registry, and grant the Project Owner role to the Cloud Workstations default service account to pull the images.
Publish the custom container images to a public Docker Hub repository using GitHub Actions. Configure Cloud Workstations to pull the public image directly using the default Compute Engine service account without enabling Container Scanning.
Create a Compute Engine VM to bake custom golden disk images daily using startup scripts. Export the disk images as compressed tar.gz archives to a Cloud Storage bucket, and configure the Workstation Configuration to boot from the Cloud Storage archive using the Storage Object Viewer role.
Store the custom container image configuration in a connected Git repository. Create a Cloud Build trigger that builds and pushes the image to a private Artifact Registry repository with the Container Scanning API enabled. Schedule the build trigger daily using Cloud Scheduler, and configure the Workstation Configuration with a service account granted the Artifact Registry Reader role.
Build custom container images manually using Docker on a local workstation, push the images to Artifact Registry, and grant the Project Owner role to the Cloud Workstations default service account to pull the images.
Publish the custom container images to a public Docker Hub repository using GitHub Actions. Configure Cloud Workstations to pull the public image directly using the default Compute Engine service account without enabling Container Scanning.
Create a Compute Engine VM to bake custom golden disk images daily using startup scripts. Export the disk images as compressed tar.gz archives to a Cloud Storage bucket, and configure the Workstation Configuration to boot from the Cloud Storage archive using the Storage Object Viewer role.
Store the custom container image configuration in a connected Git repository. Create a Cloud Build trigger that builds and pushes the image to a private Artifact Registry repository with the Container Scanning API enabled. Schedule the build trigger daily using Cloud Scheduler, and configure the Workstation Configuration with a service account granted the Artifact Registry Reader role.
This architecture establishes a fully automated, secure CI/CD lifecycle pipeline for Cloud Workstations custom container images utilizing native Google Cloud services: Cloud Build, Artifact Registry, Artifact Analysis (Container Scanning), and Cloud Scheduler.
0 1 * * *), ensuring that upstream base editor security updates are automatically pulled in daily.containerscanning.googleapis.com) enabled automatically triggers vulnerability scanning on each uploaded digest, identifying CVEs and severity levels.roles/artifactregistry.reader), granting the host VM permission to pull the private image without exposing broader permissions.This solution relies entirely on serverless, managed Google Cloud services without introducing operational overhead, third-party registry dependencies, or insecure long-lived service account keys.