How to Secure an ML Model Deployment Pipeline Against Supply Chain Attacks?

Cloud Security Architecture / DevSecOps
Answer Correct answer: A — Enable container image vulnerability scanning and enforce Binary Authorization on Artifact Registry images to secure your ML model deployment pipeline.

Your organization is building a real-time recommendation engine using ML models that process live user activity data stored in BigQuery and Cloud Storage. Each new model developed is saved to Artifact Registry. This new system deploys models to Google Kubernetes Engine, and uses Pub/Sub for message queues. Recent industry news have been reporting attacks exploiting ML model supply chains. You need to enhance the security in this serverless architecture, specifically against risks to the development and deployment pipeline. What should you do?

  1. Enable container image vulnerability scanning during development and pre-deployment. Enforce Binary Authorization on images deployed from Artifact Registry to your continuous integration and continuous deployment (CVCD) pipeline. Correct Answer
  2. Thoroughly sanitize all training data prior to model development to reduce risk of poisoning attacks. Use IAM for authorization, and apply role-based restrictions to code repositories and cloud services.
  3. Limit external libraries and dependencies that are used for the ML models as much as possible. Continuously rotate encryption keys that are used to access the user data from BigQuery and Cloud Storage.
  4. Develop strict firewall rules to limit external traffic to Cloud Run instances. Integrate intrusion detection systems (IDS) for real-time anomaly detection on Pub/Sub message flows.

Community Votes

A
75%
D
25%

75% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

Tests recognition of cloud-native supply chain defenses, with the common trap being misdirection toward training data sanitization or runtime network monitoring instead of artifact integrity.

Securing ML model supply chains requires strict artifact validation and pipeline enforcement. This page establishes why Binary Authorization and automated container scanning are the definitive controls for your CI/CD workflow.

Option D is frequently selected due to keywords like real-time and anomaly detection, but it incorrectly targets Cloud Run and proposes network controls that cannot prevent compromised containers from entering the cluster.

Community Discussion (3 comments)

JohnDohertyDoe 👍 1 Selected: A
A should be the answer. Supply chain risks happen by exploiting vulnerabilities in the images. So scanning the image and blocking deployment secures against supply chain risks. This also matches with the requirement related to the deployment pipeline.
zanhsieh 👍 1 Selected: D
The question asked "...attacks exploiting ML model supply chains" and "...risks to the development and deployment pipeline", so we should look anything related to these: A: No. Image scanning and enfore binary authorization only secure the end artifact. B and C: No. Nothing related to secure development and deployment pipeline. D: Yes, although this option just mentioned very shallow on how to implement them, e.g. IDS on pub/sub -> FortiSIEM, resticting network ingress for cloud run. https://cloud.google.com/run/docs/securing/ingress#yaml
abdelrahman89 👍 2 Selected: A
Answer A

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

The scenario emphasizes securing the development and deployment pipeline against supply chain attacks targeting ML models. Binary Authorization acts as a policy gatekeeper that validates container images stored in Artifact Registry before they reach GKE, directly preventing compromised artifacts from entering production. Pairing this with automated vulnerability scanning ensures that known weaknesses are identified and remediated prior to deployment, aligning perfectly with Google’s recommended DevSecOps practices.

Why the Other Options Are Wrong

Option B focuses on training data sanitation, which addresses data poisoning rather than artifact supply chain integrity. Option C suggests limiting dependencies and rotating encryption keys, which are general hygiene practices but do not enforce pipeline governance or prevent malicious image pushes. Option D incorrectly references Cloud Run, which is absent from the architecture, and proposes network-level controls that cannot stop a compromised container image already inside the cluster.

Community Comment Notes

Several learners correctly identified the pipeline focus, noting that "Supply chain risks happen by exploiting vulnerabilities in the images" and emphasizing pre-deployment validation. Others initially leaned toward network monitoring but quickly recognized that runtime anomaly detection does not mitigate upstream artifact tampering. The consensus accurately reflects that governance tools must precede runtime defenses in this context.

Official Reference

Exam Strategy

Always map the question's architectural components to the exact service offering; if the scenario names GKE and Artifact Registry, ignore options referencing unrelated services like Cloud Run. Prioritize pipeline governance tools over runtime defenses when asked about deployment-stage risks.

Frequently Asked Questions

Why isn't data sanitization the right choice for supply chain security?

Data sanitization prevents training-phase poisoning, whereas supply chain attacks target build artifacts and deployment pipelines. The question explicitly asks about the development and deployment stages.

Does Binary Authorization replace container scanning?

No. Scanning identifies known vulnerabilities in images, while Binary Authorization enforces admission policies to block unauthorized or unscanned images from deploying to GKE.

Related Analysis

← Back to PCSE Study Guide