Your organization recently adopted a container-based workflow for application development. Your team develops numerous applications that are deployed continuously through an automated build pipeline to a Kubernetes cluster in the production environment. The security auditor is concerned that developers or operators could circumvent automated testing and push code changes to production without approval. What should you do to enforce approvals?
A) Configure the build system with protected branches that require pull request approval.
B) Use an Admission Controller to verify that incoming requests originate from approved sources.
C) Leverage Kubernetes Role-Based Access Control (RBAC) to restrict access to only approved users.
D) Enable binary authorization inside the Kubernetes cluster and configure the build pipeline as an attestor.
Correct Answer:
Verified
Q18: You are managing the production deployment to
Q19: You use a multiple step Cloud Build
Q20: You are running an application in a
Q21: Your team has recently deployed an NGINX-based
Q22: You need to deploy a new service
Q23: You need to reduce the cost of
Q24: You support an application running on GCP
Q25: You support an application that stores product
Q27: Your application services run in Google Kubernetes
Q28: Your team uses Cloud Build for all
Unlock this Answer For Free Now!
View this answer and more for free by performing one of the following actions
Scan the QR code to install the App and get 2 free unlocks
Unlock quizzes for free by uploading documents