Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Google Professional Cloud DevOps Engineer Exam - Topic 2 Question 104 Discussion

Your company operates in a highly regulated domain. Your security team requires that only trusted container images can be deployed to Google Kubernetes Engine (GKE). You need to implement a solution that meets the requirements of the security team, while minimizing management overhead. What should you do?
D) Configure Binary Authorization in your GKE clusters to enforce deploy-time security policies
A) Grant the roles/artifactregistry. writer role to the Cloud Build service account. Confirm that no employee has Artifact Registry write permission.
B) Use Cloud Run to write and deploy a custom validator Enable an Eventarc trigger to perform validations when new images are uploaded.
C) Configure Kritis to run in your GKE clusters to enforce deploy-time security policies.

Google Professional Cloud DevOps Engineer Exam - Topic 2 Question 104 Discussion

Actual exam question for Google's Professional Cloud DevOps Engineer exam
Question #: 104
Topic #: 2
[All Professional Cloud DevOps Engineer Questions]

Your company operates in a highly regulated domain. Your security team requires that only trusted container images can be deployed to Google Kubernetes Engine (GKE). You need to implement a solution that meets the requirements of the security team, while minimizing management overhead. What should you do?

Show Suggested Answer Hide Answer
Suggested Answer: D

Contribute your Thoughts:

0/2000 characters
Mireya
4 days ago
I feel like D covers all bases. Security is a top priority!
upvoted 0 times
...
Francesco
9 days ago
True, but we need to ensure our team understands it well.
upvoted 0 times
...
Rhea
14 days ago
But D minimizes management overhead. That's crucial for us.
upvoted 0 times
...
Ashton
19 days ago
Option C is interesting too. Kritis can help with compliance.
upvoted 0 times
...
Lorita
24 days ago
I agree, Binary Authorization is robust. Less risk for us.
upvoted 0 times
...
Fletcher
30 days ago
I think option D is the best choice. It directly enforces policies.
upvoted 0 times
...
Cristina
1 month ago
Granting roles in Option A could lead to security risks if not managed properly.
upvoted 0 times
...
Kyoko
1 month ago
I’m not sure about Cloud Run for this. Seems like extra overhead.
upvoted 0 times
...
Johnetta
2 months ago
Wait, can someone explain why Kritis (Option C) isn't better?
upvoted 0 times
...
Sheridan
2 months ago
I agree, Binary Authorization is a solid way to manage trusted images.
upvoted 0 times
...
Maile
2 months ago
Option D seems like the best choice for enforcing security policies.
upvoted 0 times
...
Pedro
2 months ago
Wait, can Kritis really handle all the compliance checks?
upvoted 0 times
...
Moon
2 months ago
I agree with D, Binary Authorization is a solid solution.
upvoted 0 times
...
Naomi
2 months ago
C is interesting, but does it really minimize management overhead?
upvoted 0 times
...
Marlon
4 months ago
A sounds risky, not sure about giving write permissions.
upvoted 0 times
...
Cortney
4 months ago
I think D is the best choice for enforcing security policies.
upvoted 0 times
...
Horace
5 months ago
I feel like using Cloud Run for a custom validator could add unnecessary complexity. It might be better to stick with a built-in solution like Binary Authorization.
upvoted 0 times
...
Janna
5 months ago
I practiced a similar question where we had to restrict image deployments. I think granting roles to the service account might not be enough for security.
upvoted 0 times
...
Junita
5 months ago
I’m not entirely sure, but I think Kritis is also a good option for enforcing policies. I just can’t recall if it’s as effective as Binary Authorization.
upvoted 0 times
...
Luis
5 months ago
I remember studying about Binary Authorization and how it helps enforce security policies at deployment time. It seems like a solid choice here.
upvoted 0 times
...

Save Cancel