🔥 40% Off Crucial Exams Memberships — Deal ends today!

1 hour, 26 minutes remaining!

GCP Professional Cloud Security Engineer Practice Question

Your security team must stop Cloud Run services in the prod project from running container images unless they carry two signed attestations: one for a vulnerability scan and one for end-to-end QA. They will deploy the control in two phases: first, monitor violations without blocking deployments; later, block any new revision that lacks either attestation. All images reside in Artifact Registry, and the CI/CD pipeline already signs images at each gate. Which approach meets these goals using Google-recommended Binary Authorization practices?

  • Create two attestors (ScanGate and QAGate) and add them to a single project-wide Binary Authorization policy with requireAttestationsBy listing both attestors. Publish the policy in DRYRUN_AUDIT_LOG_ONLY mode for phase 1, monitor violations, then switch to ENFORCED_BLOCK_AND_AUDIT_LOG for phase 2.

  • Enable Binary Authorization on each Cloud Run service and use an allowlist that includes only the trusted Artifact Registry repository for phase 1; remove the allowlist in phase 2.

  • Attach an IAM deny policy to the Artifact Registry repository to block pulls of unsigned images, run it in audit-only mode for phase 1, and enforce it for phase 2.

  • Create two separate Binary Authorization policies-one requiring the vulnerability-scan attestor and another requiring the QA attestor-enabling them in successive phases.

GCP Professional Cloud Security Engineer
Managing operations
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot