Courseiva

Google PCA Practice Question: Managing and Provisioning a Solution Infrastructure

A security team wants to enforce that only container images signed by their internal CI/CD pipeline can run on GKE clusters. They also need to ensure that unsigned images are rejected at admission time. Which combination of services and configurations should they use?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Binary Authorization with Cloud KMS for signing

Binary Authorization enforces policy by requiring images to be signed by trusted signers (e.g., using Cloud KMS). It integrates with GKE admission control to block unsigned images. Cloud KMS creates and manages signing keys. Artifact Registry stores signed images but does not enforce policy. Cloud Build can be used to sign images during build, but the enforcement mechanism is Binary Authorization.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • GKE PodSecurityPolicy with allowed registries

    Why it's wrong here

    PodSecurityPolicy (deprecated) restricts pod security contexts, not image signing. It cannot enforce signature verification.

  • Binary Authorization with Cloud KMS for signing

    Why this is correct

    Binary Authorization enforces policy that only signed images can run. Cloud KMS provides the cryptographic keys for signing.

  • Cloud Build with Container Analysis

    Why it's wrong here

    Container Analysis stores metadata about images, including signatures, but does not enforce admission policies. Binary Authorization is required for enforcement.

  • Artifact Registry vulnerability scanning and IAM roles

    Why it's wrong here

    Vulnerability scanning identifies issues but does not enforce signing. IAM roles control access, not image signing.

About these practice questions

This PCA question is part of Courseiva's 955-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PCA practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCA exam.