Professional Cloud DevOps Engineer
Prepare and test your skills
Prepare and test your skills
Worked example. The correct answer is already marked and every option is explained below, so there is nothing to select here. To answer questions yourself, start the free trial.
Keep the momentum going with these hand-picked practice scenarios
Want more questions like this?
Get a free certification question every week.
Last updated
Your enterprise organization needs to standardize and enforce the CLI toolchain (including the gcloud CLI, kubectl, and terraform) across hundreds of developer environments and automated deployment pipelines.
You must prevent toolchain version drift, ensure developers and CI systems only consume approved and security-vetted toolchain versions, and establish a repeatable mechanism to review and promote version updates safely.
Which strategy should you implement?
Commit compiled binary executables of gcloud, kubectl, and terraform directly into each application's Git source repository.
Host approved versioned toolchain packages and container images in a private Artifact Registry, pin toolchain versions across environments, and automate version review workflows using Dependabot.
Configure developer shell profiles to run gcloud components update and download latest upstream binary releases of terraform and kubectl on every login session.
Use Compute Engine VM Manager OS policies to enforce apt-get upgrade and yum update package executions across developers' local machines.
Commit compiled binary executables of gcloud, kubectl, and terraform directly into each application's Git source repository.
Host approved versioned toolchain packages and container images in a private Artifact Registry, pin toolchain versions across environments, and automate version review workflows using Dependabot.
A centralized, private package repository (such as Google Cloud Artifact Registry) provides a controlled, single source of truth for hosting pre-approved, security-scanned toolchain artifacts, container images, and packages. Combining this with version pinning in configuration files guarantees that all developer workstations and automation pipelines execute against identical, validated binary versions of utilities like gcloud, kubectl, and terraform.
This architecture establishes a secure, centrally managed software supply chain. It isolates developers and CI/CD pipelines from upstream disruptions, enforces security validation before tools enter the organization, and provides an automated, auditable review process for ongoing maintenance.
Configure developer shell profiles to run gcloud components update and download latest upstream binary releases of terraform and kubectl on every login session.
Use Compute Engine VM Manager OS policies to enforce apt-get upgrade and yum update package executions across developers' local machines.