Google Professional Cloud Security Engineer exam dumps

Google Professional Cloud Security Engineer practice question 396 of 501

Professional Cloud Security Engineer. Expert level, Google Cloud. Free question with the correct answer and a full explanation.

Google Professional Cloud Security Engineer Question 396

Single answerGoogle Cloud Platform

You are a security engineer tasked with securing a Google Kubernetes Engine (GKE) cluster that runs mission-critical workloads. Your organization mandates that only container images signed and approved by the security team can be deployed to the cluster. How can you achieve this using Binary Authorization in Google Cloud?

  1. A

    Enable Binary Authorization on the GKE cluster and configure an attestor that verifies container image signatures.

  2. B

    Enable Binary Authorization on the GKE cluster and configure a policy to allow all images by default.

  3. C

    Disable Binary Authorization on the GKE cluster and use a third-party image scanning tool instead.

  4. D

    Enable Binary Authorization on the GKE cluster and configure it to automatically allow unsigned images.

Show answer and explanation

Correct answer: A

Explanation

Binary Authorization is a deploy-time security control that ensures only trusted container images are deployed to a GKE cluster or Cloud Run service. By enabling Binary Authorization and configuring an attestor, you can enforce policies that require container images to be signed and approved by the security team before they are deployed. This aligns with the organization's mandate for securing workloads.

  • A. Correct.

    This is correct. Enabling Binary Authorization on the GKE cluster and setting up an attestor ensures only signed and approved container images are permitted to run.

  • B. Incorrect.

    This is incorrect. Allowing all images by default defeats the purpose of using Binary Authorization, which is to enforce security policies for image deployment.

  • C. Incorrect.

    This is incorrect. While third-party tools can be used for image scanning, disabling Binary Authorization does not comply with the organization's requirement to enforce signed and approved images.

  • D. Incorrect.

    This is incorrect. Allowing unsigned images bypasses the security policy, which is contrary to the organization's requirement to only allow signed and approved images.

Timed practice exam

Take a Google Professional Cloud Security Engineer practice test under exam conditions

60 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam