Professional Cloud Security Engineer
Prepare and test your skills
Prepare and test your skills
Worked example. The correct answer is already marked and every option is explained below, so there is nothing to select here. To answer questions yourself, start the free trial.
Keep the momentum going with these hand-picked practice scenarios
Want more questions like this?
Get a free certification question every week.
Last updated
An enterprise organization is establishing automated security gating mechanisms within their Google Cloud CI/CD pipeline. The security policy mandates that container images deployed to production Google Kubernetes Engine (GKE) clusters must satisfy the following criteria:
MEDIUM severity or unfixable vulnerabilities above HIGH severity must be blocked from progressing to production.Which architecture should the security team implement to enforce these gating requirements?
Execute vulnerability scanning in Cloud Build using the Artifact Analysis On-Demand Scanning API, evaluate CVE severity against policy thresholds, sign the image digest using Cloud KMS to create an attestation upon passing, and enforce a Binary Authorization policy on GKE requiring that attestor with ENFORCED_BLOCK_AND_AUDIT_LOG.
Deploy Continuous Validation platform policies in Binary Authorization with a vulnerabilityCheck check set, while keeping GKE cluster admission rules configured to ALWAYS_ALLOW.
Configure Security Command Center Security Health Analytics to scan Artifact Registry, apply container metadata labels indicating scan compliance, and use GKE admission controllers with ALWAYS_DENY to evaluate label presence.
Configure Cloud Build to push images to Artifact Registry, rely on the default built-by-cloud-build attestor in Binary Authorization, and set the defaultAdmissionRule evaluationMode to ALWAYS_ALLOW with DRYRUN_AUDIT_LOG_ONLY.
Execute vulnerability scanning in Cloud Build using the Artifact Analysis On-Demand Scanning API, evaluate CVE severity against policy thresholds, sign the image digest using Cloud KMS to create an attestation upon passing, and enforce a Binary Authorization policy on GKE requiring that attestor with ENFORCED_BLOCK_AND_AUDIT_LOG.
Binary Authorization provides deploy-time policy enforcement for containerized workloads deployed across Google Kubernetes Engine (GKE). It works symbiotically with Artifact Analysis and Cloud Key Management Service (Cloud KMS) to cryptographically attest that specific quality, security, and vulnerability checks have been completed before an image descriptor is admitted to a runtime cluster.
maximumFixableSeverity: MEDIUM and maximumUnfixableSeverity: HIGH).evaluationMode: REQUIRE_ATTESTATION referencing the vulnerability attestor, and sets enforcementMode: ENFORCED_BLOCK_AND_AUDIT_LOG to block non-compliant deployments while logging events to Cloud Audit Logs.This solution prevents non-compliant or unscanned artifacts from entering production environments by enforcing a cryptographically signed gate that GKE validates before runtime pod creation.
Deploy Continuous Validation platform policies in Binary Authorization with a vulnerabilityCheck check set, while keeping GKE cluster admission rules configured to ALWAYS_ALLOW.
Configure Security Command Center Security Health Analytics to scan Artifact Registry, apply container metadata labels indicating scan compliance, and use GKE admission controllers with ALWAYS_DENY to evaluate label presence.
Configure Cloud Build to push images to Artifact Registry, rely on the default built-by-cloud-build attestor in Binary Authorization, and set the defaultAdmissionRule evaluationMode to ALWAYS_ALLOW with DRYRUN_AUDIT_LOG_ONLY.