Examtopics

Professional Cloud Security Engineer
  • Topic 1 Question 209

    Your organization is transitioning to Google Cloud. You want to ensure that only trusted container images are deployed on Google Kubernetes Engine (GKE) clusters in a project. The containers must be deployed from a centrally managed Container Registry and signed by a trusted authority.

    What should you do?

    2 つ選択
    • Enable Container Threat Detection in the Security Command Center (SCC) for the project.

    • Configure the trusted image organization policy constraint for the project.

    • Create a custom organization policy constraint to enforce Binary Authorization for Google Kubernetes Engine (GKE).

    • Enable PodSecurity standards, and set them to Restricted.

    • Configure the Binary Authorization policy with respective attestations for the project.


    シャッフルモード