Courseiva

Google PCA Design for security and compliance Practice Question

Which TWO are recommended practices for securing a Kubernetes Engine (GKE) cluster?

⚠ Common exam trap

Google Cloud often tests the misconception that disabling features like HTTP load balancing is a security best practice, when in reality it breaks functionality and security should be layered (e.g., using HTTPS, IAP, or network policies) rather than removing features.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Enable Binary Authorization to ensure only signed container images are deployed.

Option B is correct because Binary Authorization is a GKE security control that enforces deploy-time verification, allowing only container images that are attested or signed by trusted authorities to be admitted to the cluster, which prevents untrusted or tampered images from running. Option D is correct because Workload Identity is the recommended way to let GKE workloads access Google Cloud services: it binds a Kubernetes service account to an IAM service account via IAM policy bindings and the GKE metadata server, eliminating the need to export long-lived service account keys. The other options are not recommended: disabling HTTP load balancing (A) is not a standard GKE hardening practice and does not meaningfully reduce the cluster's attack surface, using the default Compute Engine service account for all nodes (C) grants overly broad, shared permissions and violates least privilege, and enabling basic authentication (E) is deprecated and insecure because it relies on static username/password credentials rather than modern identity-based access.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Disable HTTP load balancing to reduce attack surface.

    Why it's wrong here

    HTTP load balancing is how external traffic legitimately reaches services; disabling it removes required ingress rather than reducing attack surface. It is tempting because fewer exposed endpoints sound safer, and it would be correct only for clusters deliberately restricted to internal-only workloads with no public service requirements.

  • ✓

    Enable Binary Authorization to ensure only signed container images are deployed.

    Why this is correct

    Binary Authorization enforces a deploy-time admission check, permitting only container images that carry a valid signature from an attested authority. Unsigned or tampered images are rejected before scheduling, preventing supply-chain compromise of the GKE cluster.

  • ✗

    Use the default Compute Engine service account for all GKE nodes.

    Why it's wrong here

    The default Compute Engine service account carries broad project-level permissions, so every node inherits excessive access and any compromised pod can escalate. It is tempting for convenience, since nodes authenticate without extra configuration, and it would suit throwaway sandboxes where least-privilege node service accounts are not required.

  • ✓

    Use Workload Identity to bind Kubernetes service accounts to IAM service accounts.

    Why this is correct

    Workload Identity binds a Kubernetes service account to a Google Cloud IAM service account, letting pods obtain short-lived IAM credentials instead of static JSON keys stored in Secrets. This satisfies the stem's recommended-practice requirement by removing long-lived credentials, the primary leak vector in GKE clusters.

  • ✗

    Enable basic authentication for easier access management.

    Why it's wrong here

    Basic authentication transmits credentials in cleartext and bypasses modern identity controls, so it must be disabled rather than enabled. It is tempting because it appears to simplify access management, and it would only be defensible on an isolated legacy cluster with no external exposure and no IAM integration available.

About these practice questions

Courseiva writes every PCA question from scratch — 807 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PCA practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCA exam.