Professional Cloud Security EngineerEnsuring complianceHard

A heavily regulated financial institution is building a new trading platform on Google Cloud. They need to ensure that the entire software supply chain is secured, from code commit to deployment. Specifically, they require that all container images deployed to their Google Kubernetes Engine (GKE) clusters are signed by approved internal security teams and have passed vulnerability scans before they can run. What is the most effective and compliant approach?

  1. AUse Security Command Center Premium to detect non-compliant images after they are deployed.
  2. BConfigure Cloud Build to automatically scan images and then deploy them to GKE.
  3. CImplement Binary Authorization policies requiring attestations from security teams and vulnerability scanners.
  4. DSet up a custom webhook in GKE to block deployments if image metadata doesn't show a security signature.
Show answer & explanation

Correct answer: C. Implement Binary Authorization policies requiring attestations from security teams and vulnerability scanners.

Binary Authorization is purpose-built for enforcing deployment-time policies on container images. It allows requiring attestations (digital signatures) from trusted parties (security teams, vulnerability scanners) before an image can be deployed to GKE, thus securing the software supply chain effectively.

Why the other options are wrong

  • A. Security Command Center detects issues *after* deployment, which is reactive, whereas the requirement is to *prevent* non-compliant images from running.
  • B. While Cloud Build can scan, it doesn't *enforce* a block on deployment to GKE based on those scans or signatures; it's a build tool.
  • D. While possible, a custom webhook is a manual, non-managed solution that would be complex to maintain, audit, and scale compared to the native, managed Binary Authorization service.

Binary Authorization Attestations

Digital signatures or assertions made by trusted authorities (attestors) about a container image, which Binary Authorization uses to enforce deployment policies.

  • Crucial for software supply chain security.
  • Verifies image integrity and compliance before deployment.
  • Attestors can be security teams, CI/CD systems, vulnerability scanners.

Memory trick: Binary Auth demands a signed 'permission slip' before the container can launch.

More Ensuring compliance questions