Courseiva
Managing and Provisioning a Solution InfrastructuremediumMultiple ChoiceObjective-mapped

Google PCA Practice Question: Managing and Provisioning a Solution Infrastructure

Your organization requires all container images deployed to GKE to be signed by an approved authority. Which service enforces that only signed images are allowed to run?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Binary Authorization

Binary Authorization enforces policies that require images to be signed by trusted authorities before they can be deployed on GKE.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Binary Authorization

    Why this is correct

    Correct. Binary Authorization enforces image signing and attestation.

  • Cloud Asset Inventory

    Why it's wrong here

    Asset Inventory tracks resources, not image signing.

  • Artifact Registry

    Why it's wrong here

    Artifact Registry stores images but does not enforce signing policies.

  • Container Analysis

    Why it's wrong here

    Container Analysis scans for vulnerabilities, but does not enforce signing.

About these practice questions

One of 955 original PCA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PCA practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCA exam.