CV0-004 Security Practice Question
A financial services company runs a containerized payment application on Google Kubernetes Engine (GKE). A compliance auditor requires that all container images deployed to the cluster be cryptographically verified for integrity and provenance before admission. The security team wants to enforce this at the cluster level without modifying each application's deployment pipeline. Which GKE feature should they implement?
⚠ Common exam trap
Candidates often confuse image scanning tools like Container Analysis with admission enforcement mechanisms — scanning reports findings, while Binary Authorization actually blocks non-compliant images.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Binary Authorization
Binary Authorization is the GKE feature purpose-built to enforce that only images signed by trusted attestors can be deployed. Because enforcement occurs through the cluster admission controller, the policy applies centrally without requiring changes to each pipeline. The other options address network perimeters, image metadata scanning, or node hardening, none of which cryptographically verify image provenance at admission time.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
VPC Service Controls
Why it's wrong here
VPC Service Controls create a service perimeter around Google Cloud APIs to prevent data exfiltration, but they do not inspect or verify container image signatures during pod admission. They operate at the API and network boundary, not the Kubernetes admission layer, so they cannot satisfy a requirement that images be cryptographically verified before deployment to GKE.
- ✗
Container Analysis
Why it's wrong here
Container Analysis provides metadata and vulnerability scanning information about images stored in Artifact Registry, but it is a scanning and metadata service, not an enforcement mechanism. It can surface findings but does not block unsigned or unattested images from being admitted to a GKE cluster, so it alone cannot meet the auditor's enforcement requirement.
- ✗
Shielded GKE Nodes
Why it's wrong here
Shielded GKE Nodes protect node boot integrity using vTPM, secure boot, and integrity monitoring, but they harden the underlying compute instances rather than verifying the provenance of container images. They have no role in admission control for images, so they cannot enforce cryptographic verification of containers before they run.
- ✓
Binary Authorization
Why this is correct
Binary Authorization is a GKE-native admission controller that enforces attestation-based policies on container images at deploy time. It verifies cryptographic signatures produced by trusted attestors before allowing a pod to be created. This satisfies the auditor's requirement for integrity and provenance verification without touching individual pipelines, since enforcement happens centrally on the cluster's admission webhook.
Go deeper
Related to this question
About these practice questions
One of 834 original CV0-004 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This CV0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CV0-004 exam.