Courseiva
Security →mediumMultiple Choice

CV0-004 Security Practice Question

A financial services company runs a containerized payment application on Google Kubernetes Engine (GKE). A compliance auditor requires that all container images deployed to the cluster be cryptographically verified for integrity and provenance before admission. The security team wants to enforce this at the cluster level without modifying each application's deployment pipeline. Which GKE feature should they implement?

⚠ Common exam trap

Candidates often confuse image scanning tools like Container Analysis with admission enforcement mechanisms — scanning reports findings, while Binary Authorization actually blocks non-compliant images.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Binary Authorization

Binary Authorization is the GKE feature purpose-built to enforce that only images signed by trusted attestors can be deployed. Because enforcement occurs through the cluster admission controller, the policy applies centrally without requiring changes to each pipeline. The other options address network perimeters, image metadata scanning, or node hardening, none of which cryptographically verify image provenance at admission time.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    VPC Service Controls

    Why it's wrong here

    VPC Service Controls create a service perimeter around Google Cloud APIs to prevent data exfiltration, but they do not inspect or verify container image signatures during pod admission. They operate at the API and network boundary, not the Kubernetes admission layer, so they cannot satisfy a requirement that images be cryptographically verified before deployment to GKE.

  • ✗

    Container Analysis

    Why it's wrong here

    Container Analysis provides metadata and vulnerability scanning information about images stored in Artifact Registry, but it is a scanning and metadata service, not an enforcement mechanism. It can surface findings but does not block unsigned or unattested images from being admitted to a GKE cluster, so it alone cannot meet the auditor's enforcement requirement.

  • ✗

    Shielded GKE Nodes

    Why it's wrong here

    Shielded GKE Nodes protect node boot integrity using vTPM, secure boot, and integrity monitoring, but they harden the underlying compute instances rather than verifying the provenance of container images. They have no role in admission control for images, so they cannot enforce cryptographic verification of containers before they run.

  • ✓

    Binary Authorization

    Why this is correct

    Binary Authorization is a GKE-native admission controller that enforces attestation-based policies on container images at deploy time. It verifies cryptographic signatures produced by trusted attestors before allowing a pod to be created. This satisfies the auditor's requirement for integrity and provenance verification without touching individual pipelines, since enforcement happens centrally on the cluster's admission webhook.

About these practice questions

One of 834 original CV0-004 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This CV0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CV0-004 exam.