Courseiva

Google PCA Manage implementation of cloud architecture Practice Question

A healthcare company runs a patient portal on Google Kubernetes Engine (GKE). Auditors require that all container images be scanned for vulnerabilities before deployment and that only images from a trusted registry be admitted to the cluster. You are configuring Binary Authorization. Which TWO actions should you take to meet these requirements? (Choose two.)

⚠ Common exam trap

The trap here is assuming that Kubernetes PodSecurityPolicy or NetworkPolicy can restrict image sources, when only Binary Authorization evaluates image provenance at admission time.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Enable the Container Analysis API and configure a vulnerability scanning policy so that images pushed to Artifact Registry are analyzed automatically.

Binary Authorization enforces deploy-time policy based on attestations. Enabling Container Analysis provides automated vulnerability scanning of registry images, and defining an attestor that your trusted build pipeline signs ensures only verified images are admitted. Together they create a verifiable chain from scanning to admission, which satisfies the auditors' requirements.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Enable the Container Analysis API and configure a vulnerability scanning policy so that images pushed to Artifact Registry are analyzed automatically.

    Why this is correct

    Container Analysis performs automated vulnerability scanning on images in Artifact Registry and records findings as metadata. Binary Authorization attestations can be based on the results of that analysis, so enabling scanning is a prerequisite for enforcing that only scanned images are admitted. Without scanning, there is no vulnerability signal for the policy to evaluate.

  • ✓

    Create a Binary Authorization attestor and require an attestation from a trusted build pipeline before images can be deployed.

    Why this is correct

    An attestor represents a trusted authority, such as your CI/CD pipeline, that signs attestations for images it has verified. By requiring an attestation in the cluster policy, only images that passed the pipeline's checks can be admitted. This enforces the trusted-registry and scanning requirements at deploy time rather than relying on developer discipline.

  • ✗

    Apply a Kubernetes NetworkPolicy that allows egress only to the trusted registry so nodes cannot pull other images.

    Why it's wrong here

    NetworkPolicy governs network traffic between pods and to external endpoints; it does not control which container images the kubelet is permitted to run. Blocking egress to other registries is a weak, indirect control that can be bypassed by pre-pulled or cached images. It does not provide the admission-time verification the auditors require.

  • ✗

    Configure a PodSecurityPolicy that restricts images to those hosted in Artifact Registry.

    Why it's wrong here

    PodSecurityPolicy controls pod-level security settings such as privileged mode and volume types; it cannot restrict which registry an image comes from. It has also been deprecated in favor of Pod Security Admission. This option does not implement image provenance checks and therefore does not meet the requirement to admit only trusted images.

  • ✗

    Set the cluster's default namespace to use the kube-system service account for all workloads so admission checks are bypassed.

    Why it's wrong here

    Using the kube-system service account for workloads does not bypass Binary Authorization and is a poor security practice, since it grants excessive privileges. Binary Authorization enforcement is controlled by cluster-level policy, not by which service account a pod uses. This action would weaken security and fail to satisfy the auditors' admission-control requirement.

About these practice questions

This PCA question is part of Courseiva's 807-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Google Cloud exam blueprint

This PCA practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCA exam.