Google PCA Practice Question: Managing and Provisioning a Solution Infrastructure
A DevOps team uses Cloud Build to deploy Docker images to GKE. They want to ensure that only images that have passed a vulnerability scan and been signed by a trusted authority can be deployed. Which service should they integrate with Cloud Build and GKE?
⚠ Common exam trap
The trap is confusing vulnerability scanning (Artifact Analysis) with enforcement (Binary Authorization). Candidates might think that scanning alone is sufficient, but enforcement requires a policy engine like Binary Authorization.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Binary Authorization
Binary Authorization is a deploy-time security control that ensures only trusted container images are deployed to GKE. It integrates with Cloud Build to sign images after vulnerability scanning and with GKE to enforce policies that only allow signed images. This directly meets the requirement of ensuring only scanned and signed images are deployed.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Artifact Analysis
Why it's wrong here
Artifact Analysis scans container images for vulnerabilities but performs no signature verification, so unsigned images still deploy. It is tempting because it satisfies the scanning half of the requirement and integrates naturally with Artifact Registry, yet it cannot enforce that only images signed by a trusted authority reach GKE.
- ✗
Cloud Security Scanner
Why it's wrong here
Cloud Security Scanner crawls App Engine, Compute Engine and GKE web applications for XSS and mixed-content flaws; it performs no container image scanning or signature verification. It tempts because it is a Cloud-native security service, but Binary Authorization, backed by Container Analysis, is what enforces signed, scanned images at deploy time.
- ✗
Cloud Key Management Service
Why it's wrong here
Cloud KMS stores and manages encryption keys; it neither scans images for vulnerabilities nor verifies signatures at deploy time. It is tempting because signing involves keys, and KMS is correct for managing encryption keys and secrets, but the requirement needs vulnerability assessment plus signature enforcement, not key custody alone.
- ✓
Binary Authorization
Why this is correct
Binary Authorization enforces deploy-time admission control on GKE, permitting only images with valid attestations from trusted authorities. Cloud Build creates attestations after the vulnerability scan and signing steps, satisfying the stem's requirement that solely scanned, signed images reach the cluster.
Go deeper
Related to this question
Learn chapter
IAM Policies, Service Accounts, and Auditing
Key term
CAN
A CAN (Controller Area Network) is a robust vehicle bus standard designed to allow microcontrollers and devices to communicate with each other without a host computer.
Key term
Cloud Build
Cloud Build is a managed service that compiles source code into deployable artifacts, often used in continuous integration and continuous delivery pipelines.
About these practice questions
One of 807 original PCA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Google Cloud exam blueprint
This PCA practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCA exam.