🔥 40% Off Crucial Exams Memberships — Deal ends today!

9 minutes, 53 seconds remaining!

GCP Professional Cloud Security Engineer Practice Question

Your organization operates two GKE clusters, gke-dev (zonal) and gke-prod (regional), in the same Google Cloud project. Security policy mandates that only container images signed by Cloud Build may run in production. In the dev cluster, engineers should be free to deploy any image, but any policy violations must still be recorded for later review without blocking the rollout. Which Binary Authorization configuration best meets these requirements while keeping operational overhead low?

  • Create one project-level Binary Authorization policy whose defaultAdmissionRule requires a Cloud Build attestation and enforces with BLOCK_AND_AUDIT; add a clusterAdmissionRule for gke-dev that keeps REQUIRE_ATTESTATION but sets enforcementMode to DRYRUN_AUDIT_LOG_ONLY.

  • Add an admissionWhitelistPattern that matches gke-dev so its deployments bypass Binary Authorization, and set the defaultAdmissionRule to require and enforce attestations for all other clusters.

  • Disable Binary Authorization on the gke-dev cluster and configure a project-level policy for gke-prod that requires and enforces Cloud Build attestations.

  • Move gke-dev to its own Google Cloud project with Binary Authorization disabled, and keep enforcement enabled for gke-prod in the original project.

GCP Professional Cloud Security Engineer
Managing operations
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot