🔥 40% Off Crucial Exams Memberships — Deal ends today!

1 hour, 57 minutes remaining!

GCP Professional Cloud Architect Practice Question

Your company runs a secure software supply-chain pipeline on Google Cloud. Container images are built with Cloud Build and stored in a regional Artifact Registry Docker repository. The security team requires that any image containing a critical or high-severity CVE must cause the build to fail automatically, without relying on a separate deployment-time control such as Binary Authorization. Which approach should you take to meet this requirement while minimizing custom scripting?

  • Configure a Binary Authorization policy that blocks images without a vulnerability attestation for critical findings, and add the attestor to the project.

  • Move the pipeline to Container Registry and enable its automatic vulnerability scanning feature so that images with critical or high CVEs are rejected.

  • Enable continuous vulnerability scanning on the Artifact Registry repository and rely on the automatic scan that starts after the image is pushed.

  • Enable the Container Analysis API and add a Cloud Build step that runs gcloud artifacts docker images scan --format=json --severity=CRITICAL,HIGH $IMAGE_URI; configure the build to fail on a non-zero exit code.

GCP Professional Cloud Architect
Designing for security and compliance
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot