Google Professional Cloud Security Engineer exam dumps

Google Professional Cloud Security Engineer practice question 397 of 501

Professional Cloud Security Engineer. Expert level, Google Cloud. Free question with the correct answer and a full explanation.

Google Professional Cloud Security Engineer Question 397

Select 3Google Cloud Platform

Your organization is deploying containerized applications on Google Kubernetes Engine (GKE) and wants to ensure that only trusted container images are used in the environment. You are tasked with configuring Binary Authorization to enforce this requirement. What steps must you take to implement Binary Authorization correctly?

  1. A

    Enable Binary Authorization on the GKE cluster.

  2. B

    Create and configure an attestor to verify signed container images.

  3. C

    Add the required permissions to the Kubernetes Service Account used by your application pods.

  4. D

    Define a policy in Binary Authorization that specifies which images are allowed to be deployed.

  5. E

    Use Cloud KMS to encrypt the container images before deployment.

Show answer and explanation

Correct answers: A, B, D

Explanation

Binary Authorization helps secure GKE clusters by allowing only trusted container images to be deployed. The implementation involves enabling Binary Authorization on the cluster, creating an attestor to verify signed images, and defining a policy that specifies which images are allowed. Permissions for Kubernetes Service Accounts and Cloud KMS encryption are unrelated to Binary Authorization configuration.

  • A. Correct.

    Correct. Enabling Binary Authorization on the GKE cluster ensures that the cluster enforces policies to verify that only trusted container images are deployed.

  • B. Correct.

    Correct. Configuring an attestor is necessary to verify that the container images are signed by a trusted entity.

  • C. Incorrect.

    Incorrect. While Kubernetes Service Accounts are important for application-level permissions, they are not directly related to configuring Binary Authorization.

  • D. Correct.

    Correct. Defining a policy in Binary Authorization is required to specify the rules for allowed container images.

  • E. Incorrect.

    Incorrect. Cloud KMS is not used to encrypt container images in the context of Binary Authorization.

Timed practice exam

Take a Google Professional Cloud Security Engineer practice test under exam conditions

60 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam