Google Professional Cloud Security Engineer exam dumps

Google Professional Cloud Security Engineer practice question 398 of 501

Professional Cloud Security Engineer. Expert level, Google Cloud. Free question with the correct answer and a full explanation.

Google Professional Cloud Security Engineer Question 398

Select 3Google Cloud Platform

Your organization uses Google Kubernetes Engine (GKE) to deploy containerized applications. To enhance security, you are tasked with configuring Binary Authorization to ensure only verified container images are deployed. What steps should you take to enforce Binary Authorization for your GKE cluster?

  1. A

    Enable the Binary Authorization feature on the GKE cluster.

  2. B

    Create an attestor with a public key to verify signed container images.

  3. C

    Configure a policy in Binary Authorization to allow unsigned images for testing purposes.

  4. D

    Deploy a signed container image and verify that the attestor approves it.

  5. E

    Grant the GKE service account the 'Binary Authorization Admin' role.

Show answer and explanation

Correct answers: A, B, D

Explanation

To secure your GKE cluster with Binary Authorization, you must enable the feature on the cluster, create an attestor to verify signed container images, and test the setup by deploying a signed container image. This ensures that only verified images are deployed, enhancing the security of your workloads. Allowing unsigned images or assigning unnecessary roles does not align with best practices for securing GKE with Binary Authorization.

  • A. Correct.

    Correct: Enabling Binary Authorization on the GKE cluster is necessary to enforce policies on container images.

  • B. Correct.

    Correct: An attestor with a public key is required to verify that signed container images meet the defined policies.

  • C. Incorrect.

    Incorrect: Allowing unsigned images for testing undermines the purpose of Binary Authorization to enforce security.

  • D. Correct.

    Correct: Deploying a signed container image tests the configuration and ensures that the attestor approves valid images.

  • E. Incorrect.

    Incorrect: The 'Binary Authorization Admin' role is not required for the GKE service account. This role is typically assigned to administrators managing Binary Authorization policies.

Timed practice exam

Take a Google Professional Cloud Security Engineer practice test under exam conditions

60 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam