nerdexam
GoogleGoogle

PROFESSIONAL-CLOUD-DEVOPS-ENGINEER · Question #87

PROFESSIONAL-CLOUD-DEVOPS-ENGINEER Question #87: Real Exam Question with Answer & Explanation

Sign in or unlock PROFESSIONAL-CLOUD-DEVOPS-ENGINEER to reveal the answer and full explanation for question #87. The question stem and answer options stay visible for context.

Submitted by asante_acc· Apr 18, 2026Building and implementing CI/CD pipelines for a service

Question

As part of your company's initiative to shift left on security, the InfoSec team is asking all teams to implement guard rails on all the Google Kubernetes Engine (GKE) clusters to only allow the deployment of trusted and approved images. You need to determine how to satisfy the InfoSec team's goal of shifting left on security. What should you do?

Options

  • AEnable Container Analysis in Artifact Registry, and check for common vulnerabilities and
  • BUse Binary Authorization to attest images during your CI/CD pipeline
  • CConfigure Identity and Access Management (IAM) policies to create a least privilege model on
  • DDeploy Falco or Twistlock on GKE to monitor for vulnerabilities on your running Pods

Unlock PROFESSIONAL-CLOUD-DEVOPS-ENGINEER to see the answer

You've previewed enough free PROFESSIONAL-CLOUD-DEVOPS-ENGINEER questions. Unlock PROFESSIONAL-CLOUD-DEVOPS-ENGINEER for full answers, explanations, the timed quiz mode, progress tracking, and the master PDF. Question stem and options stay visible so you can still see what's on the exam.

Topics

#Binary Authorization#GKE Security#Shift Left Security#Image Deployment
Full PROFESSIONAL-CLOUD-DEVOPS-ENGINEER PracticeBrowse All PROFESSIONAL-CLOUD-DEVOPS-ENGINEER Questions