Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Google Professional Cloud DevOps Engineer Exam - Topic 2 Question 104 Discussion

Your company operates in a highly regulated domain. Your security team requires that only trusted container images can be deployed to Google Kubernetes Engine (GKE). You need to implement a solution that meets the requirements of the security team, while minimizing management overhead. What should you do?
D) Configure Binary Authorization in your GKE clusters to enforce deploy-time security policies
A) Grant the roles/artifactregistry. writer role to the Cloud Build service account. Confirm that no employee has Artifact Registry write permission.
B) Use Cloud Run to write and deploy a custom validator Enable an Eventarc trigger to perform validations when new images are uploaded.
C) Configure Kritis to run in your GKE clusters to enforce deploy-time security policies.

Google Professional Cloud DevOps Engineer Exam - Topic 2 Question 104 Discussion

Actual exam question for Google's Professional Cloud DevOps Engineer exam
Question #: 104
Topic #: 2
[All Professional Cloud DevOps Engineer Questions]

Your company operates in a highly regulated domain. Your security team requires that only trusted container images can be deployed to Google Kubernetes Engine (GKE). You need to implement a solution that meets the requirements of the security team, while minimizing management overhead. What should you do?

Show Suggested Answer Hide Answer
Suggested Answer: D

Contribute your Thoughts:

0/2000 characters
Maile
3 hours ago
Option D seems like the best choice for enforcing security policies.
upvoted 0 times
...
Pedro
5 days ago
Wait, can Kritis really handle all the compliance checks?
upvoted 0 times
...
Moon
10 days ago
I agree with D, Binary Authorization is a solid solution.
upvoted 0 times
...
Naomi
16 days ago
C is interesting, but does it really minimize management overhead?
upvoted 0 times
...
Marlon
2 months ago
A sounds risky, not sure about giving write permissions.
upvoted 0 times
...
Cortney
2 months ago
I think D is the best choice for enforcing security policies.
upvoted 0 times
...
Horace
3 months ago
I feel like using Cloud Run for a custom validator could add unnecessary complexity. It might be better to stick with a built-in solution like Binary Authorization.
upvoted 0 times
...
Janna
3 months ago
I practiced a similar question where we had to restrict image deployments. I think granting roles to the service account might not be enough for security.
upvoted 0 times
...
Junita
3 months ago
I’m not entirely sure, but I think Kritis is also a good option for enforcing policies. I just can’t recall if it’s as effective as Binary Authorization.
upvoted 0 times
...
Luis
3 months ago
I remember studying about Binary Authorization and how it helps enforce security policies at deployment time. It seems like a solid choice here.
upvoted 0 times
...

Save Cancel