Courseiva

Google PCA Practice Question: Managing Implementation and Ensuring Solution and Operations Reliability

A healthcare company runs a critical application on Google Kubernetes Engine (GKE) that processes patient data. The compliance team requires that all container images be scanned for vulnerabilities before deployment, and that only images from a trusted registry be allowed. The security team wants to enforce this policy across all clusters in the organization. They also need to audit any attempts to deploy untrusted images. Which combination of Google Cloud services should they use?

⚠ Common exam trap

A common mix-up: candidates confuse vulnerability scanning with policy enforcement; scanning alone does not prevent deployment of vulnerable images.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Use Binary Authorization with a policy that requires attestations from a trusted authority, and enable audit logging for GKE.

Binary Authorization is the Google Cloud service designed to enforce deploy-time policies on GKE by requiring attestations. By setting a policy that requires attestations from a trusted authority, the company ensures that only images that have been built and scanned by trusted processes are admitted. Enabling audit logging provides a record of all deployment attempts, including those that violate the policy. This satisfies both the enforcement and auditing requirements across all clusters in the organization.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Enable GKE Sandbox on all nodes and use Anthos Config Management to apply a policy that restricts image registries.

    Why it's wrong here

    GKE Sandbox provides an extra layer of isolation for containers but does not scan images or enforce image registry policies. Anthos Config Management can apply policies, but it does not natively integrate with vulnerability scanning or attestation. While it can restrict registries, it lacks the deploy-time attestation verification that Binary Authorization provides. This option addresses isolation and policy enforcement but not the specific requirement for vulnerability scanning and attestation.

  • ✗

    Use Container Analysis to scan images and configure a GKE admission controller to reject images with vulnerabilities.

    Why it's wrong here

    Container Analysis provides vulnerability scanning and metadata but does not enforce deployment policies by itself. A GKE admission controller can reject images based on custom logic, but it is not a managed service and requires custom development and maintenance. The scenario asks for an organization-wide policy and audit, which this approach does not provide out of the box. It also does not ensure that only images from a trusted registry are allowed unless additional custom logic is implemented.

  • ✗

    Use Artifact Registry with vulnerability scanning enabled and configure IAM policies to restrict which projects can pull images.

    Why it's wrong here

    Artifact Registry can scan images for vulnerabilities and IAM policies can restrict access, but this does not enforce that only scanned images are deployed to GKE. A developer with pull access could still deploy an unscanned image from another registry if the cluster allows it. There is no deploy-time verification or audit of deployment attempts. This option provides registry-level controls but not the required enforcement and auditing at the cluster level.

  • ✓

    Use Binary Authorization with a policy that requires attestations from a trusted authority, and enable audit logging for GKE.

    Why this is correct

    Binary Authorization enforces deploy-time policies on GKE by requiring attestations that prove an image was built by a trusted builder and scanned for vulnerabilities. By configuring a policy that requires attestations from a trusted authority, the company ensures only compliant images are deployed. Enabling audit logging captures attempts to deploy non-compliant images, satisfying the audit requirement. This combination directly addresses both enforcement and auditing across all clusters in the organization.

About these practice questions

This PCA question is part of Courseiva's 807-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Google Cloud exam blueprint

This PCA practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCA exam.