Google PCA Designing for Security and Compliance Practice Question
An organization requires that all container images deployed to GKE be signed and verified before deployment. Which GCP service should be used?
⚠ Common exam trap
PCA often tests the difference between image scanning (vulnerability detection) and image signing/verification (policy enforcement). Candidates may confuse vulnerability scanning with Binary Authorization's enforcement role.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Binary Authorization
Binary Authorization is a GCP service that enforces deploy-time security controls on GKE by ensuring only trusted container images are deployed. It uses attestations created by trusted authorities to verify that an image has been signed and meets specific criteria before allowing deployment. This directly satisfies the requirement for signed and verified images.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Container Registry vulnerability scanning
Why it's wrong here
Vulnerability scanning inspects images for known CVEs; it does not verify cryptographic signatures or attestations. It is tempting because it is a security control applied to container images. Deployment-time signature enforcement requires Binary Authorization, which validates attestations before admitting workloads to GKE.
- ✓
Binary Authorization
Why this is correct
Binary Authorization enforces deploy-time attestation on GKE, blocking unsigned or unverified container images before they reach the cluster. It satisfies the stem's requirement for signature verification at deployment by validating attestations from trusted authorities, unlike vulnerability scanning or registry-level controls, which cannot gate admission.
- ✗
Cloud Build
Why it's wrong here
Cloud Build compiles and packages images; it can sign as a build step but does not verify signatures at deploy time. It is tempting because build pipelines often handle signing. Enforcement at admission is Binary Authorization's role, checking attestations before GKE runs the image.
- ✗
Artifact Registry
Why it's wrong here
Artifact Registry stores and manages container images but does not perform signature verification at deployment. It is tempting because it is the image repository, so signing artefacts live there. Binary Authorization is the service that enforces attestation checks before GKE admits a pod.
Go deeper
Related to this question
Learn chapter
Security Best Practices and Compliance
Key term
GKE
GKE is Google's managed Kubernetes service that automates deploying, scaling, and managing containerized applications in the cloud.
Key term
Binary Authorization
Binary Authorization is a security control that ensures only trusted container images are deployed in a Kubernetes or cloud environment.
About these practice questions
This PCA question is part of Courseiva's 807-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Google Cloud exam blueprint
This PCA practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCA exam.