Professional Cloud Security EngineerEnsuring complianceMedium

A global enterprise with highly sensitive data needs to ensure that all virtual machine (VM) images deployed across their Google Cloud organization adhere to a strict set of security policies, including specific operating system versions and patches. They want to prevent the deployment of any non-compliant images. Which Google Cloud service should they use to enforce this?

  1. ACloud Security Command Center
  2. BOrganization Policy Service
  3. CBinary Authorization
  4. DCompute Engine Image Policies
Show answer & explanation

Correct answer: C. Binary Authorization

Binary Authorization is designed to enforce policies on deployable artifacts, including VM images, ensuring that only trusted and compliant images are deployed to Compute Engine or GKE.

Why the other options are wrong

  • A. Cloud Security Command Center is for threat detection and vulnerability management, not deployment policy enforcement.
  • B. Organization Policy Service can set constraints, but Binary Authorization is specifically for enforcing policies on binaries/images before deployment.
  • D. Compute Engine Image Policies are not a specific Google Cloud service for broad organizational enforcement; rather, you'd use OS policies or Binary Authorization.

Binary Authorization

A Google Cloud service that provides software supply chain security by enforcing deployment policies on container images and VM images.

  • Prevents deployment of unauthorized or non-compliant binaries.
  • Integrates with CI/CD pipelines and vulnerability scanners.
  • Supports attestation by trusted authorities.

Memory trick: Binary Auth checks the image's passport before it can fly.

More Ensuring compliance questions