GCP Professional Cloud Architect Practice Question
Your company operates dozens of GKE clusters spread across multiple projects. Security requires that:
Only container images built in the central prod-build project may be deployed anywhere.
Each image must pass Artifact Registry's built-in vulnerability scanning before deployment.
Signing keys have to be centrally managed in a separate security project, rotated automatically every 90 days, and never handled directly by cluster operators. Which approach best enforces these requirements while minimizing manual effort?
Configure Cloud Build in the prod-build project to generate Container Analysis attestations signed with a Cloud KMS key stored in a dedicated security project that rotates every 90 days, and enforce an organization-level Binary Authorization policy requiring that attestor and passing vulnerability scans on all GKE clusters.
Publish images from Cloud Build to Artifact Registry, then deploy Anthos Policy Controller with custom OPA Gatekeeper constraints that verify image digests; store rotating signing secrets in Secret Manager for operators to apply during deployments.
Place Artifact Registry and all GKE clusters inside the same VPC Service Controls perimeter, enforce PodSecurityPolicies that allow only images from that registry, and configure automatic rotation on project-level KMS keys without using Binary Authorization.
Grant the prod-build Cloud Build service account exclusive push access to Artifact Registry and enable vulnerability scanning; use image path whitelists in cluster-level Binary Authorization policies and manage signing keys manually when needed.
Integrating Cloud Build with Binary Authorization lets Cloud Build automatically generate Container Analysis provenance and create an attestation each time it finishes a build. If Cloud Build is configured to sign those attestations with a Cloud KMS key that resides in a dedicated security project, operators never handle the private key material. Enabling automatic rotation on that key satisfies the 90-day rotation mandate. An organization-level Binary Authorization policy that requires an attestor backed by the same key-and enforces that images have no high-severity vulnerabilities-prevents any GKE cluster from running images that are not built and signed in the prod-build project or whose scans fail. The remaining options rely on access controls, custom admission controllers, or network boundaries but do not provide cryptographic attestations tied to centralized, auto-rotated keys, so they cannot guarantee both provenance and scanning compliance with minimal ongoing effort.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
How does Binary Authorization ensure security in GKE clusters?
Open an interactive chat with Bash
What is an attestation and how does it tie to signing keys?
Open an interactive chat with Bash
Why is centralized key management important for security projects?
Open an interactive chat with Bash
What is Binary Authorization in GCP?
Open an interactive chat with Bash
How does Artifact Registry's vulnerability scanning work?
Open an interactive chat with Bash
What are Cloud KMS keys, and how does key rotation improve security?
Open an interactive chat with Bash
GCP Professional Cloud Architect
Designing for security and compliance
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99 $11.99
$11.99/mo
Billed monthly, Cancel any time.
$19.99 after promotion ends
3 Month Pass
$44.99 $26.99
$8.99/mo
One time purchase of $26.99, Does not auto-renew.
$44.99 after promotion ends
Save $18!
MOST POPULAR
Annual Pass
$119.99 $71.99
$5.99/mo
One time purchase of $71.99, Does not auto-renew.
$119.99 after promotion ends
Save $48!
BEST DEAL
Lifetime Pass
$189.99 $113.99
One time purchase, Good for life.
Save $76!
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .