Courseiva

Google PCA Practice Question: Managing Implementation and Ensuring Solution and Operations Reliability

Your organization runs a global e-commerce platform on Google Kubernetes Engine (GKE). The security team requires that all container images deployed to the cluster are scanned for vulnerabilities and that deployments are blocked if critical vulnerabilities are found. They also want to minimize operational overhead. What should you do?

⚠ Common exam trap

The trap here is assuming that vulnerability scanning alone can block deployments, when in fact scanning only reports findings and requires an enforcement mechanism like Binary Authorization to prevent deployment.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Enable Binary Authorization in the cluster and configure a policy that requires attestations from a vulnerability scanner before deployment.

Binary Authorization is a Google Cloud service that enforces deploy-time policies by requiring attestations. By integrating with Container Analysis, you can automatically attest only images that pass vulnerability scanning, and the policy blocks images without attestations. This automates enforcement and reduces manual review, satisfying both security and operational efficiency.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Configure a Kubernetes admission controller that calls the Container Analysis API to check for vulnerabilities and rejects pods with critical findings.

    Why it's wrong here

    While a custom admission controller can check vulnerabilities, it requires development and maintenance effort, increasing operational overhead. Binary Authorization provides a managed, declarative way to enforce attestations without building custom logic. The scenario emphasizes minimizing overhead, making a managed solution preferable.

  • ✗

    Enable Pod Security Policies to restrict images to those from trusted registries, and rely on registry scanning to prevent vulnerable images.

    Why it's wrong here

    Pod Security Policies (deprecated) do not scan for vulnerabilities; they enforce pod-level security contexts. Registry scanning alone does not block deployments; it only reports findings. This approach neither automatically blocks vulnerable images nor meets the requirement to prevent their deployment.

  • ✗

    Use Cloud Build to scan images with Container Analysis, and manually review the scan results before approving each deployment.

    Why it's wrong here

    Manual review does not automatically block deployments and introduces operational overhead, contradicting the goal to minimize overhead. It relies on human intervention, which is error-prone and not scalable for a global platform. Automated enforcement is needed to consistently block images with critical vulnerabilities.

  • ✓

    Enable Binary Authorization in the cluster and configure a policy that requires attestations from a vulnerability scanner before deployment.

    Why this is correct

    Binary Authorization enforces deploy-time security controls by verifying attestations. You can integrate a vulnerability scanner (e.g., Container Analysis) to create attestations only for images that pass scanning. This blocks non-compliant images and reduces manual effort, aligning with the requirement to block critical vulnerabilities with minimal overhead.

About these practice questions

One of 807 original PCA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Google Cloud exam blueprint

This PCA practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCA exam.