Pre-Winter Sale Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: force70

Google Certified Professional - Cloud Architect (GCP) Professional-Cloud-Architect Question # 32 Topic 4 Discussion

Google Certified Professional - Cloud Architect (GCP) Professional-Cloud-Architect Question # 32 Topic 4 Discussion

Professional-Cloud-Architect Exam Topic 4 Question 32 Discussion:
Question #: 32
Topic #: 4

You are designing a new insurance claims processing application that will be deployed on Google Kubernetes Engine (GKE). Your company ' s compliance team requires a complete and non-repudiable audit trail for all administrative actions from day one. Your application must capture who deploys a new container image, who modifies the GKE cluster ' s configuration, and who interacts with running pods or Kubernetes secrets using kubectl. What should you do?


A.

Enable Binary Authorization on the GKE cluster and create a policy that requires all deployed container images to be signed by a trusted attestor.


B.

Enable GKE Audit Logging to send Kubernetes API server logs to Cloud Logging, and ensure Cloud Audit Logs are enabled for the project.


C.

Activate the Security Command Center Premium tier to analyze GKE logs and detect threats, vulnerabilities, and misconfigurations in real time.


D.

Deploy a DaemonSet to every node in the GKE cluster that runs a logging agent to collect and forward all container logs to Cloud Logging.


Get Premium Professional-Cloud-Architect Questions

Contribute your Thoughts:


Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.