🔥 40% Off Crucial Exams Memberships — Deal ends today!

2 hours, 27 minutes remaining!

GCP Professional Cloud Security Engineer Practice Question

Your organization builds container images with Cloud Build and stores them in Artifact Registry. Security requirements state that any image containing Critical or High-severity vulnerabilities must cause the CI pipeline to fail immediately, and all scan findings must be visible in Security Command Center for later review. Which solution best meets these requirements with minimal custom code?

  • Enable Artifact Registry vulnerability scanning, create a Binary Authorization policy that blocks images with High or Critical CVEs, and add a Cloud Build attestation step that signs only if the scan passes.

  • Enable vulnerability scanning on the repository and rely on Cloud Build's default build failure when Container Analysis reports Critical CVEs.

  • Run a custom gcloud step in Cloud Build that polls Container Analysis for scan results and exits with code 1 if any High-severity finding is returned.

  • Move the build to a Cloud Build private pool and enable Cloud IDS inline scanning to quarantine any images with Critical CVEs before the build finishes.

GCP Professional Cloud Security Engineer
Managing operations
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot