Professional Cloud DevOps Engineer
Prepare and test your skills
Prepare and test your skills
Worked example. The correct answer is already marked and every option is explained below, so there is nothing to select here. To answer questions yourself, start the free trial.
Keep the momentum going with these hand-picked practice scenarios
Want more questions like this?
Get a free certification question every week.
Last updated
Your enterprise is establishing an end-to-end software supply chain security architecture for containerized microservices deployed to Google Kubernetes Engine (GKE).
Your design must satisfy the following requirements:
Which strategy should you implement?
Execute the On-Demand Scanning API manually from developer workstations during local builds, write the scan output to Cloud Logging, and configure GKE Network Policies to block traffic from non-compliant pods.
Enable Artifact Analysis for continuous vulnerability scanning in Artifact Registry, configure Cloud Build to generate SLSA build provenance and attestations, and enforce Binary Authorization deploy-time policies on GKE combined with Continuous Validation (CV).
Configure Anthos Config Sync with read-only OCI authentication to pull manifests from Artifact Registry, and rely on signed Git commits to verify supply chain integrity at deploy time.
Deploy a self-hosted Harbor registry instance on Compute Engine with the 'Automatically scan images on push' option enabled, export container logs to BigQuery, and use custom Kubernetes admission controllers to evaluate image hashes.
Execute the On-Demand Scanning API manually from developer workstations during local builds, write the scan output to Cloud Logging, and configure GKE Network Policies to block traffic from non-compliant pods.
Enable Artifact Analysis for continuous vulnerability scanning in Artifact Registry, configure Cloud Build to generate SLSA build provenance and attestations, and enforce Binary Authorization deploy-time policies on GKE combined with Continuous Validation (CV).
This architecture establishes a complete, automated software supply chain security framework across Google Cloud by combining Artifact Analysis, Cloud Build, and Binary Authorization with Continuous Validation (CV).
This design provides a unified, cloud-native control plane across Google Cloud managed services, meeting all compliance and security requirements without adding third-party operational burdens or complex self-managed tooling.
Configure Anthos Config Sync with read-only OCI authentication to pull manifests from Artifact Registry, and rely on signed Git commits to verify supply chain integrity at deploy time.
Deploy a self-hosted Harbor registry instance on Compute Engine with the 'Automatically scan images on push' option enabled, export container logs to BigQuery, and use custom Kubernetes admission controllers to evaluate image hashes.