nerdexam
Google

PROFESSIONAL-CLOUD-DEVOPS-ENGINEER · Question #88

Your company operates in a highly regulated domain. Your security team requires that only trusted container images can be deployed to Google Kubernetes Engine (GKE). You need to implement a solution t

Sign in or unlock PROFESSIONAL-CLOUD-DEVOPS-ENGINEER to reveal the answer and full explanation for question #88. The question stem and answer options stay visible for context.

Submitted by diego_uy· Apr 18, 2026Building and implementing CI/CD pipelines for a service

Question

Your company operates in a highly regulated domain. Your security team requires that only trusted container images can be deployed to Google Kubernetes Engine (GKE). You need to implement a solution that meets the requirements of the security team while minimizing management overhead. What should you do?

Options

  • AConfigure Binary Authorization in your GKE clusters to enforce deploy-time security policies.
  • BGrant the roles/artifactregistry.writer role to the Cloud Build service account. Confirm that no
  • CUse Cloud Run to write and deploy a custom validator. Enable an Eventarc trigger to perform
  • DConfigure Kritis to run in your GKE clusters to enforce deploy-time security policies.

Unlock PROFESSIONAL-CLOUD-DEVOPS-ENGINEER to see the answer

You've previewed enough free PROFESSIONAL-CLOUD-DEVOPS-ENGINEER questions. Unlock PROFESSIONAL-CLOUD-DEVOPS-ENGINEER for full answers, explanations, the timed quiz mode, progress tracking, and the master PDF. Question stem and options stay visible so you can still see what's on the exam.

Topics

#Container Security#Google Kubernetes Engine (GKE)#Binary Authorization#Deployment Policies
Full PROFESSIONAL-CLOUD-DEVOPS-ENGINEER Practice