An unhandled error has occurred.
Reload
X
UIZFORGE
Exams
Pricing
Career Paths
Resources
EN
Login
Sign Up
1
/ 5
Advanced
A security team requires that GKE only runs container images built by the trusted Cloud Build pipeline. The control must reject untrusted images at deploy time, not merely report them later. Which supply-chain control should be added?
Enable Artifact Analysis only and review vulnerability reports during the next sprint.
Grant cluster-admin only to the CI service account and trust developers not to deploy manually.
Use Cloud Audit Logs to detect manual kubectl apply commands after they happen.
Use Binary Authorization with attestations from the trusted build pipeline and an enforcing admission policy.
AI Tutor
Stuck? Get a hint