🔥 40% Off Crucial Exams Memberships — Deal ends today!

1 hour, 26 minutes remaining!

GCP Professional Cloud Architect Practice Question

Your company is standardizing its CI/CD workflows on Cloud Build. Security architects require that every container image pushed to Artifact Registry include verifiable build provenance so that runtime environments can confirm the image's origin before deployment. Which design best meets this requirement while minimizing operational toil?

  • Use Container-Optimized OS signatures to verify node images; application containers inherit trust from the host so no additional provenance is required.

  • Configure a Cloud Function trigger that signs each built image with a separately managed KMS key before pushing to Container Registry.

  • Enable Cloud Build's build provenance feature and push images to Artifact Registry; then configure Binary Authorization to require trusted Cloud Build provenance attestations before allowing deployments.

  • Export build logs to Cloud Logging and require operations teams to manually verify image digests against the logs prior to deployment.

GCP Professional Cloud Architect
Designing for security and compliance
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot