How to Enforce Verified Container Deployment Policies
Your organization is worried about recent news headlines regarding application vulnerabilities in production applications that have led to security breaches. You want to automatically scan your deployment pipeline for vulnerabilities and ensure only scanned and verified containers can run in the environment. What should you do?
Community Votes
100% of anonymous learners picked answer D. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
Tests understanding of deployment-time policy enforcement versus simple pipeline scanning, where candidates often confuse CLI verification commands with runtime admission control.
Binary Authorization enforces deployment policies by requiring verified container attestations. This page establishes why admission control is required to block unscanned images in GKE.
Option B is frequently chosen because it performs vulnerability scanning, but it lacks the admission controller capability to actually block unauthorized containers from running in the cluster.
Community Discussion (3 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
Binary Authorization acts as an admission controller for GKE clusters, evaluating whether incoming container images meet organizational policies before deployment. By integrating your CI/CD pipeline to generate attestations upon successful vulnerability scans, you create a cryptographic proof of compliance. The platform then strictly blocks any workload lacking these valid attestations, directly satisfying the requirement to ensure only verified containers run.Why the Other Options Are Wrong
Option A focuses on identity and access management for cluster administrators rather than image provenance. Option B demonstrates how to query artifact registry for vulnerabilities, which is useful for reporting but cannot enforce runtime deployment restrictions. Option C provides developer-side IDE feedback during coding, which occurs too early in the lifecycle and bypasses centralized pipeline enforcement.Community Comment Notes
Multiple learners validated the selection, noting that official documentation directly links attestations to automated pipeline verification. As BondleB observed, the service architecture specifically bridges scanning results with cluster admission gates. Consensus confirms that generating attestations is the definitive mechanism for meeting exam objectives around trusted supply chains.Official Reference
Exam Strategy
Focus on distinguishing between scanning tools and admission controllers. When a question emphasizes ensuring only verified workloads can run, prioritize policy enforcement services like Binary Authorization over standalone scanning or IAM configurations.
Frequently Asked Questions
Why isn't gcloud artifacts describe enough for this scenario?
It only queries image metadata and reports findings. It cannot block deployments or enforce admission policies at runtime.
How do attestations integrate with CI/CD pipelines?
Pipeline tools sign images and upload attestations to Artifact Registry after passing scans, which Binary Authorization then validates before deployment.