GCP Professional Cloud Architect Practice Question
Your organization has two GKE clusters in the same project: stg-cluster for feature testing and prod-cluster for customer traffic. Images are built by Cloud Build and pushed to Artifact Registry. Compliance requires prod-cluster to block any image that is not signed by Cloud Build, while stg-cluster must still run unsigned images but log any violations. You need the simplest solution with minimal long-term upkeep. What should you do?
Enable Binary Authorization only on prod-cluster with a policy that requires an attestation from Cloud Build; leave stg-cluster without Binary Authorization.
Create a Gatekeeper constraint template that validates image digests and apply it solely to prod-cluster, leaving stg-cluster unchanged.
Enable Binary Authorization on both clusters; set the policy to require a Cloud Build attestation and run in Log-only mode on stg-cluster but in Block and Audit mode on prod-cluster.
Restrict Artifact Registry so only prod-cluster's service account can pull images and isolate stg-cluster with VPC Service Controls.
Binary Authorization provides per-cluster enforcement modes. Setting the policy to ENFORCED_BLOCK_AND_AUDIT_LOG on prod-cluster guarantees that only images carrying a valid attestation from a Cloud Build attestor are admitted. The same policy can be attached to stg-cluster but placed in LOG_ONLY (dry-run) mode so deployments continue while violations are still recorded for visibility. Leveraging Cloud Build's built-in attestor avoids manual signing and requires no custom controllers, giving the lowest operational burden.
Other options either eliminate the required logging (disabling Binary Authorization on stg-cluster), introduce custom Gatekeeper logic that must be written and maintained, or attempt to solve the problem with network controls that do not verify image provenance.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is Binary Authorization?
Open an interactive chat with Bash
What is the difference between ENFORCED_BLOCK_AND_AUDIT_LOG and LOG_ONLY modes in Binary Authorization?
Open an interactive chat with Bash
Why choose Cloud Build as the attestor for signing container images?
Open an interactive chat with Bash
What is Binary Authorization in GCP?
Open an interactive chat with Bash
What is an attestation in the context of Binary Authorization?
Open an interactive chat with Bash
What are the main enforcement modes in Binary Authorization?
Open an interactive chat with Bash
GCP Professional Cloud Architect
Designing for security and compliance
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .