Google PCA Practice Question: Analysing and Optimising Technical and Business Processes
Your company uses a CI/CD pipeline that builds container images and stores them in Artifact Registry. The images are deployed to Google Kubernetes Engine (GKE). You need to ensure that only images that have been scanned for vulnerabilities and approved by a security team can be deployed to the production GKE cluster. You want to enforce this policy automatically without modifying the CI/CD pipeline. What should you do?
⚠ Common exam trap
Many candidates confuse vulnerability scanning with deployment enforcement; scanning alone does not block unapproved images from being deployed.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Enable Binary Authorization on the GKE cluster and configure a policy that requires attestations from the security team's attestor.
Binary Authorization enforces deploy-time policies on GKE by requiring cryptographic attestations that prove an image was scanned and approved. The security team can sign attestations after scanning, and the GKE cluster will only admit images with valid attestations. This meets the requirement without altering the CI/CD pipeline and provides automated enforcement.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Configure a Kubernetes admission webhook that calls the security team's API to validate each image before deployment.
Why it's wrong here
A custom admission webhook can enforce policies, but it requires developing and maintaining the webhook, and it modifies the cluster configuration. The requirement is to avoid modifying the CI/CD pipeline, but this adds operational overhead and potential failure points. Binary Authorization is a managed, purpose-built solution that integrates with GKE and attestations.
- ✗
Restrict Artifact Registry permissions so that only the security team can push images to the production repository.
Why it's wrong here
Restricting push permissions controls who can upload images, but it does not ensure that images are scanned and approved before deployment. A developer with push access could still upload an unscanned image, and the GKE cluster would deploy it. This approach addresses supply chain ingress but not deploy-time enforcement of approvals.
- ✓
Enable Binary Authorization on the GKE cluster and configure a policy that requires attestations from the security team's attestor.
Why this is correct
Binary Authorization is a deploy-time security control that ensures only trusted container images are deployed on GKE. By configuring a policy that requires an attestation from the security team's attestor, only images that have been scanned and approved can be admitted. This enforcement happens at the cluster level without changing the CI/CD pipeline.
- ✗
Use Container Analysis to scan images and set a vulnerability threshold that blocks deployment if any critical vulnerability is found.
Why it's wrong here
Container Analysis provides vulnerability scanning and metadata but does not enforce deployment policies on GKE by itself. It can inform decisions, but without a policy engine like Binary Authorization, it cannot automatically block deployment of unapproved images. The security team's manual approval step would still be missing from the enforcement.
Go deeper
Related to this question
Learn chapter
IAM Policies, Service Accounts, and Auditing
Key term
Image
An image is a complete snapshot of a system's operating system, applications, and settings, used to deploy or restore computing environments quickly.
Key term
Artifact Registry
Artifact Registry is a managed service for storing, managing, and securing container images and other software packages in a centralized repository.
About these practice questions
One of 807 original PCA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Google Cloud exam blueprint
This PCA practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCA exam.