GCP Professional Cloud Security Engineer Practice Question
Your organization will enforce Binary Authorization so only container images that pass vulnerability scanning can run on production GKE clusters. Cloud Build already signs each image digest with an asymmetric Cloud KMS key, and the policy requires an attestation from an attestor named prod-vuln-scan. To finish configuring prod-vuln-scan so GKE can verify the CI/CD signatures at deployment, what must you add to the attestor?
The public key that corresponds to the private key the CI/CD pipeline uses to sign the image digest.
The Artifact Registry repository URI that hosts the image so the attestor can locate its layers.
The private key from Cloud KMS so Binary Authorization can decrypt the signature during deployment.
The Cloud Build trigger ID that built the image so Binary Authorization can look up its provenance.
An attestor stores one or more public cryptographic keys (or Cloud KMS key-version references). At deploy time, Binary Authorization verifies that at least one public key in each required attestor can validate an attestation over the image digest. The private key used by the CI/CD pipeline remains securely in Cloud KMS; only the corresponding public key (or its key-version reference) is registered with the attestor. Referencing a build trigger, repository URI, or uploading the private key would not enable signature verification.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is Binary Authorization in GKE?
Open an interactive chat with Bash
What is an attestor in Binary Authorization?
Open an interactive chat with Bash
How does Cloud KMS private and public keys work with Binary Authorization?
Open an interactive chat with Bash
What is Binary Authorization in GKE?
Open an interactive chat with Bash
What is the role of an attestor in Binary Authorization?
Open an interactive chat with Bash
How does Cloud Build integrate with Binary Authorization?
Open an interactive chat with Bash
GCP Professional Cloud Security Engineer
Managing operations
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .