How to Enforce Verified Container Deployment Policies

Container Security & Policy Enforcement
Answer Correct answer: D — Enable Binary Authorization to enforce deployment policies that require valid vulnerability scan attestations before allowing containers to run.

Your organization is worried about recent news headlines regarding application vulnerabilities in production applications that have led to security breaches. You want to automatically scan your deployment pipeline for vulnerabilities and ensure only scanned and verified containers can run in the environment. What should you do?

  1. Use Kubernetes role-based access control (RBAC) as the source of truth for cluster access by granting “container.clusters.get” to limited users. Restrict deployment access by allowing these users to generate a kubeconfig file containing the configuration access to the GKE cluster.
  2. Use gcloud artifacts docker images describe LOCATION-docker.pkg.dev/PROJECT_ID/REPOSITORY/IMAGE_ID@sha256:HASH --show-package-vulnerability in your CI/CD pipeline, and trigger a pipeline failure for critical vulnerabilities.
  3. Enforce the use of Cloud Code for development so users receive real-time security feedback on vulnerable libraries and dependencies before they check in their code.
  4. Enable Binary Authorization and create attestations of scans. Correct Answer

Community Votes

D
100%

100% of anonymous learners picked answer D. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

Tests understanding of deployment-time policy enforcement versus simple pipeline scanning, where candidates often confuse CLI verification commands with runtime admission control.

Binary Authorization enforces deployment policies by requiring verified container attestations. This page establishes why admission control is required to block unscanned images in GKE.

Option B is frequently chosen because it performs vulnerability scanning, but it lacks the admission controller capability to actually block unauthorized containers from running in the cluster.

Community Discussion (3 comments)

BondleB 👍 2
https://cloud.google.com/binary-authorization/docs/attestations D
jmaquino 👍 2
D: https://cloud.google.com/binary-authorization/docs/making-attestations?hl=es-419
abdelrahman89 👍 2 Selected: D
Answer D

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

Binary Authorization acts as an admission controller for GKE clusters, evaluating whether incoming container images meet organizational policies before deployment. By integrating your CI/CD pipeline to generate attestations upon successful vulnerability scans, you create a cryptographic proof of compliance. The platform then strictly blocks any workload lacking these valid attestations, directly satisfying the requirement to ensure only verified containers run.

Why the Other Options Are Wrong

Option A focuses on identity and access management for cluster administrators rather than image provenance. Option B demonstrates how to query artifact registry for vulnerabilities, which is useful for reporting but cannot enforce runtime deployment restrictions. Option C provides developer-side IDE feedback during coding, which occurs too early in the lifecycle and bypasses centralized pipeline enforcement.

Community Comment Notes

Multiple learners validated the selection, noting that official documentation directly links attestations to automated pipeline verification. As BondleB observed, the service architecture specifically bridges scanning results with cluster admission gates. Consensus confirms that generating attestations is the definitive mechanism for meeting exam objectives around trusted supply chains.

Official Reference

Exam Strategy

Focus on distinguishing between scanning tools and admission controllers. When a question emphasizes ensuring only verified workloads can run, prioritize policy enforcement services like Binary Authorization over standalone scanning or IAM configurations.

Frequently Asked Questions

Why isn't gcloud artifacts describe enough for this scenario?

It only queries image metadata and reports findings. It cannot block deployments or enforce admission policies at runtime.

How do attestations integrate with CI/CD pipelines?

Pipeline tools sign images and upload attestations to Artifact Registry after passing scans, which Binary Authorization then validates before deployment.

Related Analysis

← Back to PCSE Study Guide