nerdexam
Google

PROFESSIONAL-CLOUD-ARCHITECT · Question #300

You are designing a new insurance claims processing application that will be deployed on Google Kubernetes Engine (GKE) Your company's compliance team requires a complete and non- repudiable audit tra

Sign in or unlock PROFESSIONAL-CLOUD-ARCHITECT to reveal the answer and full explanation for question #300. The question stem and answer options stay visible for context.

Submitted by ashley.k· Mar 30, 2026Designing for security and compliance

Question

You are designing a new insurance claims processing application that will be deployed on Google Kubernetes Engine (GKE) Your company's compliance team requires a complete and non- repudiable audit trail for all administrative actions from day one. Your application must capture who deploys a new container image, who modifies the GKE cluster's configuration, and who interacts with running pods or Kubernetes secrets using kubectl. What should you do?

Options

  • AEnable Binary Authorization on the GKE cluster, and create a policy that requires all deployed
  • BDeploy a DaemonSet to every node in the GKE cluster that runs a logging agent to collect and
  • CEnable GKE Audit Logging to send Kubernetes API server logs to Cloud Logging, and ensure
  • DActivate the Security Command Center Premium tier to analyze GKE logs and detect threats,

Unlock PROFESSIONAL-CLOUD-ARCHITECT to see the answer

You've previewed enough free PROFESSIONAL-CLOUD-ARCHITECT questions. Unlock PROFESSIONAL-CLOUD-ARCHITECT for full answers, explanations, the timed quiz mode, progress tracking, and the master PDF. Question stem and options stay visible so you can still see what's on the exam.

Topics

#GKE audit logging#Cloud Logging#audit trail#compliance
Full PROFESSIONAL-CLOUD-ARCHITECT Practice