You need a build pipeline for images that will run on GKE and you want to ensure only pipeline-built images can be deployed. Which set of Google Cloud services should you use?
Choose an answer
Tap an option to check your answer.
Correct answer: Cloud Build, Artifact Registry, and Binary Authorization.
Why this is the answer
The correct answer is Cloud Build, Artifact Registry, and Binary Authorization. Cloud Build is essential for automating the build process of container images from source code. Artifact Registry is the recommended service for storing and managing these container images securely and privately. Binary Authorization is crucial for enforcing deployment policies on GKE, ensuring that only images signed by trusted builders (like Cloud Build) can be deployed. This combination directly addresses the requirement of building images and ensuring only pipeline-built images are deployable. Cloud Storage is not the primary service for storing container images; Artifact Registry is designed for this purpose. Google Cloud Deploy is for orchestrating deployments across environments, not for image storage or security enforcement. Google Cloud Armor is a WAF/DDoS protection service, unrelated to image build, storage, or deployment authorization.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed