Professional Cloud Security EngineerEnsuring complianceEasy
A software company is building a highly regulated financial application on Google Cloud. They need to ensure that all container images deployed to production environments originate from trusted, authorized sources and have passed specific security scans. Any attempt to deploy an unapproved image must be blocked. Which Google Cloud service addresses this requirement?
- AContainer Registry
- BBinary Authorization
- CArtifact Registry
- DSecurity Command Center
Show answer & explanationAnswer & explanation
Correct answer: B. Binary Authorization
Binary Authorization enforces deployment policies for container images, ensuring only trusted and verified images are deployed to Google Kubernetes Engine (GKE) or Cloud Run. It allows defining attestation policies that must be met before deployment.
Why the other options are wrong
- A. Container Registry stores and manages Docker images but doesn't enforce deployment policies.
- C. Artifact Registry is a universal package manager for various artifact types, including containers, but doesn't enforce deployment policies.
- D. Security Command Center is a security management and data risk platform, not a deployment policy enforcer for containers.
Binary Authorization
A Google Cloud service that provides software supply chain security by enforcing deployment policies for container images to Google Kubernetes Engine (GKE) and Cloud Run.
- Ensures only trusted, signed images are deployed.
- Blocks deployment of unauthorized or non-compliant images.
- Integrates with CI/CD pipelines and security scanning tools.
Memory trick: Binary Authorization is the 'Bouncer' for your containers – if it's not on the list, it's not getting in.