QuestionQ44

Security Engineering

A security engineer needs to ensure production containers are automatically scanned for vulnerabilities before they are accepted into the production environment. Which of the following should the engineer use to automatically incorporate vulnerability scanning on every commit?

Explanation

A CI/CD pipeline is the automation layer that builds and promotes container images on every commit, so adding an image-scanning step there enforces automatic vulnerability scanning as a gate before anything reaches production. Code repositories and IDEs merely store or edit code and have no build-and-gate mechanism to enforce this automatically.

Community Discussion

No comments yet. Be the first to start the discussion!