Courseiva

Google PCA Practice Question: Managing and Provisioning a Solution Infrastructure

Your organization requires all container images deployed to GKE to be signed by an approved authority. Which service enforces that only signed images are allowed to run?

⚠ Common exam trap

The trap is conflating the scanner (Container Analysis) with the enforcer (Binary Authorization) — the exam expects you to know that scanning alone does not prevent deployment.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Binary Authorization

Binary Authorization is a deploy-time security control on GKE and Cloud Run that only permits container images that satisfy a defined policy — typically requiring attestations from trusted authorities (e.g., a vulnerability scanner or a signing step in the CI pipeline). It integrates with Container Analysis, which stores the attestations, but Binary Authorization is the component that actually blocks unsigned or unattested images from being admitted to the cluster.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Binary Authorization

    Why this is correct

    Binary Authorization enforces deploy-time admission control on GKE, verifying cryptographic signatures against attestors you define before permitting a pod to start. This directly satisfies the stem's requirement that only images signed by an approved authority may run, blocking unsigned or unverified images at admission rather than merely scanning them afterwards.

  • ✗

    Cloud Asset Inventory

    Why it's wrong here

    Cloud Asset Inventory records and exports resource metadata and change history; it performs no admission decision on pod creation, so unsigned images still run. It is tempting as a visibility tool, and would be correct for auditing which images exist across projects, not for enforcing signatures at deploy time.

  • ✗

    Artifact Registry

    Why it's wrong here

    Artifact Registry stores and serves container images with vulnerability scanning; it does not block GKE from running an unsigned image. It is tempting because it hosts the images, and would be correct for image storage, access control and lifecycle, not for signature verification during admission.

  • ✗

    Container Analysis

    Why it's wrong here

    Container Analysis attaches metadata and vulnerability findings to images; it reports on artefacts rather than denying admission, so unsigned images still deploy. It is tempting because it inspects image contents, and would be correct for provenance metadata and CVE reporting, not for enforcing signed-image policy.

About these practice questions

One of 807 original PCA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Google Cloud exam blueprint

This PCA practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCA exam.