Professional Cloud ArchitectDesign for security and complianceHard

A global software company maintains a large repository of container images in Artifact Registry. They have a strict security policy requiring that all container images deployed into production environments must be scanned for known vulnerabilities and approved by a security team before deployment. How can they automate the enforcement of this policy within Google Cloud?

  1. AConfigure Cloud DLP to scan container image layers for sensitive data.
  2. BUse Cloud Build to run vulnerability scans during image creation.
  3. CImplement Binary Authorization with Container Analysis integration.
  4. DApply IAM conditions to restrict deployment permissions based on image tags.
Show answer & explanation

Correct answer: C. Implement Binary Authorization with Container Analysis integration.

Binary Authorization is a deploy-time security control that enforces policies on images being deployed to GKE or Cloud Run. When integrated with Container Analysis, it can check for vulnerability scan results and require attestations (approvals) from security teams before allowing deployment, directly addressing the policy requirements.

Why the other options are wrong

  • A. Cloud DLP identifies sensitive data within content, not for vulnerability scanning or deploy-time policy enforcement on container images.
  • B. Cloud Build can run scans, but it doesn't *enforce* that only scanned and approved images are deployed into production; it's a build-time tool.
  • D. IAM conditions can restrict based on tags, but tags alone don't provide vulnerability scan results or a formal approval process. This is a weak enforcement mechanism for this specific policy.

Binary Authorization

Binary Authorization is a deploy-time security control that enforces policies on images deployed to Google Kubernetes Engine (GKE) or Cloud Run.

  • Prevents deployment of unauthorized or non-compliant images.
  • Integrates with Container Analysis for vulnerability insights.
  • Requires attestations (approvals) for images before deployment.

Memory trick: Binary Authorization is the security checkpoint for your container images before they can sail.

More Design for security and compliance questions