Cloud Digital Leader Google Cloud Products and Services Practice Question
A team is designing a CI/CD pipeline for a microservices application. They want to automatically build container images from source code, store them securely, and deploy to GKE. Which THREE services should they include? (Choose three.)
⚠ Common exam trap
GCDL often tests the confusion between Cloud Run and GKE as deployment targets, or between Cloud Storage and Artifact Registry for storing images; candidates must match the services to the specific requirements of building, storing, and deploying to GKE.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Cloud Build
Cloud Build (A) is correct because it is Google Cloud's managed CI/CD service that compiles source code and builds container images, and it integrates natively with GKE and Artifact Registry for automated pipelines. Artifact Registry (D) is correct because it securely stores and manages container images (and other artifacts) with IAM-based access control and vulnerability scanning, serving as the image repository the pipeline pushes to and GKE pulls from. GKE (E) is correct because it is the target runtime for deploying the containerized microservices, and it can pull images directly from Artifact Registry within the same project. Cloud Storage (B) is not the right choice because it is object storage for blobs, not a container image registry with the tagging and vulnerability features needed here. Cloud Run (C) is not correct because it is a serverless container platform, not the GKE deployment target specified in the scenario.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Cloud Build
Why this is correct
Cloud Build is the fully managed CI/CD service that compiles your source code, runs tests, and builds the container image from a Dockerfile or build config. It executes the build steps defined in your pipeline, generating OCI-compliant images that are then pushed to a registry. This makes Cloud Build the correct core engine for the CI/CD pipeline.
- ✗
Cloud Storage
Why it's wrong here
Cloud Storage is an object storage service designed for unstructured data like backups, media files, and static assets, not for storing container images. While it can be used for build artifacts or caching, it does not provide the Docker Registry v2 API, vulnerability scanning, or IAM-based access control needed for container image distribution. Artifact Registry is the proper service for securely storing and managing the built container images.
- ✗
Cloud Run
Why it's wrong here
Cloud Run is a serverless container platform that runs stateless HTTP services on a fully managed infrastructure, but the team's deployment target is GKE, which requires Kubernetes clusters and manifest-based orchestration. Cloud Run abstracts away cluster operations, making it a completely different execution model from GKE. Therefore, when GKE is explicitly specified, Cloud Run is not the correct deployment target for this microservices pipeline.
- ✓
Artifact Registry
Why this is correct
Artifact Registry is a private container image repository that fully supports Docker and OCI images, providing a secure location to store the images built by Cloud Build. It integrates natively with Cloud Build and GKE, offering IAM controls, vulnerability scanning, and VPC-SC compatibility. After Cloud Build builds the images, they are pushed to Artifact Registry, from which GKE pulls them for deployment.
- ✓
GKE
Why this is correct
GKE is a managed Kubernetes service that provides the orchestration platform for deploying and running containerized microservices at scale. In this pipeline, GKE is the deployment target that receives the container images from Artifact Registry and schedules them onto the cluster. With features like autoscaling, load balancing, and rolling updates, GKE is the correct environment to run the microservices application.
Quick reference
Cloud Service Model Comparison
| Model | You Manage | Provider Manages | Examples |
|---|---|---|---|
| IaaS | OS, runtime, apps, data | Hardware, hypervisor, networking | EC2, Azure VMs, GCP Compute Engine |
| PaaS | Apps and data | OS, runtime, middleware, hardware | Elastic Beanstalk, Azure App Service |
| SaaS | Data and settings only | Everything else | Microsoft 365, Salesforce, Workday |
| FaaS / Serverless | Function code only | Infra, scaling, runtime | Lambda, Azure Functions, Cloud Run |
| CaaS | Containers and apps | Kubernetes, OS, hardware | EKS, AKS, GKE |
Go deeper
Related to this question
Learn chapter
Cloud Run for Serverless Containers
Key term
IAM
Identity and Access Management (IAM) is a framework of policies and technologies that ensures the right individuals have the appropriate access to technology resources.
Key term
Container
A container is a lightweight, standalone software package that includes everything needed to run an application, such as code, runtime, system tools, and libraries.
About these practice questions
This GCDL question is part of Courseiva's 848-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Google Cloud exam blueprint
This GCDL practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCDL exam.