Professional Cloud Security Engineer
Prepare and test your skills
Prepare and test your skills
Worked example. The correct answer is already marked and every option is explained below, so there is nothing to select here. To answer questions yourself, start the free trial.
Keep the momentum going with these hand-picked practice scenarios
Want more questions like this?
Get a free certification question every week.
Last updated
A financial services organization is implementing a CI/CD pipeline using Cloud Build and Artifact Registry for containerized microservices. The security team establishes a strict shift-left security policy:
CRITICAL or HIGH severity are identified.Which pipeline orchestration strategy should the security engineer implement in cloudbuild.yaml?
Push the image to Artifact Registry, execute gcloud container images describe --show-package-vulnerability in a post-build step, and initiate a pipeline rollback if CVEs exceed policy thresholds.
Upload the image to Artifact Registry to trigger Automatic Scanning, subscribe a Cloud Function to the gcr Pub/Sub topic, and delete the image asynchronously if CRITICAL or HIGH vulnerabilities are reported.
Execute an on-demand scan using gcloud artifacts docker images scan on the locally built container image, evaluate the findings with gcloud artifacts docker images list-vulnerabilities, and fail the build step prior to executing docker push if target severities are detected.
Deploy the container image to Google Kubernetes Engine (GKE) and enforce a Binary Authorization policy requiring vulnerability attestations to block runtime pod scheduling.
Push the image to Artifact Registry, execute gcloud container images describe --show-package-vulnerability in a post-build step, and initiate a pipeline rollback if CVEs exceed policy thresholds.
Upload the image to Artifact Registry to trigger Automatic Scanning, subscribe a Cloud Function to the gcr Pub/Sub topic, and delete the image asynchronously if CRITICAL or HIGH vulnerabilities are reported.
Execute an on-demand scan using gcloud artifacts docker images scan on the locally built container image, evaluate the findings with gcloud artifacts docker images list-vulnerabilities, and fail the build step prior to executing docker push if target severities are detected.
On-Demand Scanning (ODS) is a feature of Artifact Analysis that allows developers and automated build pipelines to initiate vulnerability scans on local container images before pushing them to a container repository. Unlike automated registry scanning, which triggers only after an image is uploaded, On-Demand Scanning allows scanning directly within the Cloud Build workspace.
cloudbuild.yaml, the image is built locally using docker build. The build pipeline calls gcloud artifacts docker images scan against the local image tag, generating an on-demand scan resource without requiring the image to be uploaded to Artifact Registry.gcloud artifacts docker images list-vulnerabilities with a filter for vulnerability.effectiveSeverity. By checking for regular expression matches against CRITICAL|HIGH, the script exits with code 1 if matched, terminating the Cloud Build execution.docker push step from ever running, ensuring no vulnerable artifacts reach the registry.CRITICAL, HIGH, or MEDIUM) tailored to organizational compliance policies.This approach natively satisfies shift-left security requirements by scanning the artifact inside the build execution environment and conditioning repository publication on passing vulnerability thresholds.
Deploy the container image to Google Kubernetes Engine (GKE) and enforce a Binary Authorization policy requiring vulnerability attestations to block runtime pod scheduling.