Google PCA Practice Question: Managing and Provisioning a Solution Infrastructure
A security team wants to enforce that only container images signed by their internal CI/CD pipeline can run on GKE clusters. They also need to ensure that unsigned images are rejected at admission time. Which combination of services and configurations should they use?
⚠ Common exam trap
PCA often tests the difference between vulnerability scanning (Container Analysis/Artifact Registry) and admission-time signature enforcement (Binary Authorization) — candidates pick scanning options thinking they enforce signing.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Binary Authorization with Cloud KMS for signing
Binary Authorization is the GKE feature that enforces admission-time policies requiring container images to be signed by trusted authorities. Cloud KMS provides the signing keys used by the CI/CD pipeline to create attestations. Together they ensure only images signed by the internal pipeline are admitted to the cluster.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
GKE PodSecurityPolicy with allowed registries
Why it's wrong here
PodSecurityPolicy governs pod-level security contexts and volume types, not image signature verification, so it cannot reject unsigned images at admission. It is tempting because restricting allowed registries limits image sources, which suits policy enforcement generally. However, signature validation requires Binary Authorization with a Container Analysis attestor, enforced via GKE admission control.
- ✓
Binary Authorization with Cloud KMS for signing
Why this is correct
Binary Authorization enforces admission-time policy on GKE, verifying image signatures against attestors before pods deploy. Cloud KMS holds the asymmetric signing key the CI/CD pipeline uses to sign images, so only pipeline-signed images pass and unsigned ones are rejected at admission.
- ✗
Cloud Build with Container Analysis
Why it's wrong here
Cloud Build builds images and Container Analysis stores metadata and vulnerability findings, but neither enforces signature verification at admission. Rejecting unsigned images on GKE requires Binary Authorization configured with an attestor and enforced on the cluster.
- ✗
Artifact Registry vulnerability scanning and IAM roles
Why it's wrong here
Artifact Registry scanning detects vulnerabilities and IAM roles control access, but neither verifies image signatures nor rejects unsigned images at admission. Enforcing signed-only deployment on GKE requires Binary Authorization with an attestor and enforcement enabled.
Go deeper
Related to this question
Learn chapter
IAM Policies, Service Accounts, and Auditing
Key term
CAN
A CAN (Controller Area Network) is a robust vehicle bus standard designed to allow microcontrollers and devices to communicate with each other without a host computer.
Key term
GKE
GKE is Google's managed Kubernetes service that automates deploying, scaling, and managing containerized applications in the cloud.
About these practice questions
This PCA question is part of Courseiva's 807-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Google Cloud exam blueprint
This PCA practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCA exam.