Courseiva

Google PCA Practice Question: Managing and Provisioning a Solution Infrastructure

A DevOps team uses Cloud Build to deploy Docker images to GKE. They want to ensure that only images that have passed a vulnerability scan and been signed by a trusted authority can be deployed. Which service should they integrate with Cloud Build and GKE?

⚠ Common exam trap

The trap is confusing vulnerability scanning (Artifact Analysis) with enforcement (Binary Authorization). Candidates might think that scanning alone is sufficient, but enforcement requires a policy engine like Binary Authorization.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Binary Authorization

Binary Authorization is a deploy-time security control that ensures only trusted container images are deployed to GKE. It integrates with Cloud Build to sign images after vulnerability scanning and with GKE to enforce policies that only allow signed images. This directly meets the requirement of ensuring only scanned and signed images are deployed.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Artifact Analysis

    Why it's wrong here

    Artifact Analysis scans container images for vulnerabilities but performs no signature verification, so unsigned images still deploy. It is tempting because it satisfies the scanning half of the requirement and integrates naturally with Artifact Registry, yet it cannot enforce that only images signed by a trusted authority reach GKE.

  • ✗

    Cloud Security Scanner

    Why it's wrong here

    Cloud Security Scanner crawls App Engine, Compute Engine and GKE web applications for XSS and mixed-content flaws; it performs no container image scanning or signature verification. It tempts because it is a Cloud-native security service, but Binary Authorization, backed by Container Analysis, is what enforces signed, scanned images at deploy time.

  • ✗

    Cloud Key Management Service

    Why it's wrong here

    Cloud KMS stores and manages encryption keys; it neither scans images for vulnerabilities nor verifies signatures at deploy time. It is tempting because signing involves keys, and KMS is correct for managing encryption keys and secrets, but the requirement needs vulnerability assessment plus signature enforcement, not key custody alone.

  • ✓

    Binary Authorization

    Why this is correct

    Binary Authorization enforces deploy-time admission control on GKE, permitting only images with valid attestations from trusted authorities. Cloud Build creates attestations after the vulnerability scan and signing steps, satisfying the stem's requirement that solely scanned, signed images reach the cluster.

About these practice questions

One of 807 original PCA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Google Cloud exam blueprint

This PCA practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCA exam.