Professional Cloud DevOps Engineer
Prepare and test your skills
Prepare and test your skills
Worked example. The correct answer is already marked and every option is explained below, so there is nothing to select here. To answer questions yourself, start the free trial.
Keep the momentum going with these hand-picked practice scenarios
Want more questions like this?
Get a free certification question every week.
Last updated
Your organization is establishing a secure CI/CD deployment pipeline for containerized microservices running on Google Kubernetes Engine (GKE). The security team has defined the following compliance requirements:
Which combination of steps should you implement to configure this deployment gate?
Enable Artifact Analysis scanning on the repository. Deploy a custom admission webhook in GKE to query Artifact Analysis CVSS scores during pod scheduling. Set the Binary Authorization policy default rule to ALWAYS_ALLOW. In the CI/CD pipeline, tag the container image with a unique build ID, sign the tag name with a private key, and deploy the workload to GKE using the mutable image tag.
Enable Artifact Analysis scanning on the repository. Configure the GKE cluster with Binary Authorization evaluation mode set to Audit-only with Continuous Validation. In the CI/CD pipeline, sign the Git commit SHA using an asymmetric private key and store the signature as a Kubernetes annotation on the deployment manifest before deploying to GKE.
Enable Artifact Analysis vulnerability scanning. In Binary Authorization, set the admission rule to ALWAYS_DENY and grant the roles/binaryauthorization.attestorsVerifier role to the GKE service account. In the CI/CD pipeline, trigger the Binary Authorization breakglass workflow upon detecting acceptable scan scores to bypass policy checks and deploy the image.
Enable Artifact Analysis vulnerability scanning on the repository. Create a Binary Authorization attestor associated with an Artifact Analysis note and register the PKIX public key. Configure the Binary Authorization policy default admission rule to require attestations from this attestor and enable enforcement on the GKE cluster. In the pipeline, evaluate the scan results, sign the container image digest with the private key to create an attestation occurrence, and deploy the workload to GKE using the image digest.
Enable Artifact Analysis scanning on the repository. Deploy a custom admission webhook in GKE to query Artifact Analysis CVSS scores during pod scheduling. Set the Binary Authorization policy default rule to ALWAYS_ALLOW. In the CI/CD pipeline, tag the container image with a unique build ID, sign the tag name with a private key, and deploy the workload to GKE using the mutable image tag.
Enable Artifact Analysis scanning on the repository. Configure the GKE cluster with Binary Authorization evaluation mode set to Audit-only with Continuous Validation. In the CI/CD pipeline, sign the Git commit SHA using an asymmetric private key and store the signature as a Kubernetes annotation on the deployment manifest before deploying to GKE.
Enable Artifact Analysis vulnerability scanning. In Binary Authorization, set the admission rule to ALWAYS_DENY and grant the roles/binaryauthorization.attestorsVerifier role to the GKE service account. In the CI/CD pipeline, trigger the Binary Authorization breakglass workflow upon detecting acceptable scan scores to bypass policy checks and deploy the image.
Enable Artifact Analysis vulnerability scanning on the repository. Create a Binary Authorization attestor associated with an Artifact Analysis note and register the PKIX public key. Configure the Binary Authorization policy default admission rule to require attestations from this attestor and enable enforcement on the GKE cluster. In the pipeline, evaluate the scan results, sign the container image digest with the private key to create an attestation occurrence, and deploy the workload to GKE using the image digest.
Binary Authorization is a deploy-time security control that ensures only trusted and verified container images are deployed to Google Kubernetes Engine (GKE). It integrates directly with Artifact Analysis, which automatically scans container images stored in Artifact Registry for known vulnerabilities (Common Vulnerabilities and Exposures - CVEs) and records metadata notes and occurrences.
image@sha256:...) rather than mutable tags guarantees that the cryptographic signature matches the exact bits being executed, preventing tag-swapping or drift.This approach uses native Google Cloud security services to form an automated, end-to-end software supply chain security gate. It eliminates manual intervention while guaranteeing that only cryptographically signed, vulnerability-free container digests are admitted into the production GKE environment.