Examtopics

Professional Cloud DevOps Engineer
  • Topic 1 Question 134

    As part of your company's initiative to shift left on security, the InfoSec team is asking all teams to implement guard rails on all the Google Kubernetes Engine (GKE) clusters to only allow the deployment of trusted and approved images. You need to determine how to satisfy the InfoSec team's goal of shifting left on security. What should you do?

    • Enable Container Analysis in Artifact Registry, and check for common vulnerabilities and exposures (CVEs) in your container images

    • Use Binary Authorization to attest images during your CI/CD pipeline

    • Configure Identity and Access Management (IAM) policies to create a least privilege model on your GKE clusters.

    • Deploy Falco or Twistlock on GKE to monitor for vulnerabilities on your running Pods


    シャッフルモード