Google PCA Practice Question: Managing and Provisioning a Solution Infrastructure
Your organization requires all container images deployed to GKE to be signed by an approved authority. Which service enforces that only signed images are allowed to run?
⚠ Common exam trap
The trap is conflating the scanner (Container Analysis) with the enforcer (Binary Authorization) — the exam expects you to know that scanning alone does not prevent deployment.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Binary Authorization
Binary Authorization is a deploy-time security control on GKE and Cloud Run that only permits container images that satisfy a defined policy — typically requiring attestations from trusted authorities (e.g., a vulnerability scanner or a signing step in the CI pipeline). It integrates with Container Analysis, which stores the attestations, but Binary Authorization is the component that actually blocks unsigned or unattested images from being admitted to the cluster.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Binary Authorization
Why this is correct
Binary Authorization enforces deploy-time admission control on GKE, verifying cryptographic signatures against attestors you define before permitting a pod to start. This directly satisfies the stem's requirement that only images signed by an approved authority may run, blocking unsigned or unverified images at admission rather than merely scanning them afterwards.
- ✗
Cloud Asset Inventory
Why it's wrong here
Cloud Asset Inventory records and exports resource metadata and change history; it performs no admission decision on pod creation, so unsigned images still run. It is tempting as a visibility tool, and would be correct for auditing which images exist across projects, not for enforcing signatures at deploy time.
- ✗
Artifact Registry
Why it's wrong here
Artifact Registry stores and serves container images with vulnerability scanning; it does not block GKE from running an unsigned image. It is tempting because it hosts the images, and would be correct for image storage, access control and lifecycle, not for signature verification during admission.
- ✗
Container Analysis
Why it's wrong here
Container Analysis attaches metadata and vulnerability findings to images; it reports on artefacts rather than denying admission, so unsigned images still deploy. It is tempting because it inspects image contents, and would be correct for provenance metadata and CVE reporting, not for enforcing signed-image policy.
Go deeper
Related to this question
Learn chapter
Cloud SQL and Managed Data Stores
Key term
Organization
An Organization is a top-level container in Google Cloud that represents your company or entities and serves as the root node for all your cloud resources, policies, and access control.
Key term
Binary Authorization
Binary Authorization is a security control that ensures only trusted container images are deployed in a Kubernetes or cloud environment.
About these practice questions
One of 807 original PCA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Google Cloud exam blueprint
This PCA practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCA exam.