Question 206 of 318
Choose 2Your organization is transitioning to Google Cloud. You want to ensure that only trusted container images are deployed on Google Kubernetes Engine (GKE) clusters in a project. The containers must be deployed from a centrally managed Container Registry and signed by a trusted authority.
What should you do? (Choose two.)
AEnable Container Threat Detection in the Security Command Center (SCC) for the project.
BConfigure the trusted image organization policy constraint for the project.
✓CCreate a custom organization policy constraint to enforce Binary Authorization for Google Kubernetes Engine (GKE).
DEnable PodSecurity standards, and set them to Restricted.
✓EConfigure the Binary Authorization policy with respective attestations for the project.
✓
Correct Answer: C, E
Create a custom organization policy constraint to enforce Binary Authorization for Google Kubernetes Engine (GKE).
▥
Explanation
The correct answer is highlighted above. Review the wording carefully, then use the next question to continue building your understanding of Google certification topics.