QuestionQ7

Security Engineering

A security engineer is assisting a DevOps team that has the following requirements for container images:

• Ensure container images are hashed and use version controls.

• Ensure container images are up to date and scanned for vulnerabilities.

Which of the following should the security engineer do to meet these requirements?

Explanation

Adding hashing, version control, currency, and vulnerability scanning as automated gates within the CI/CD pipeline ensures every container image is verified and up to date before it can be promoted, directly satisfying both stated requirements. Cluster mesh ACLs, audit-only monitoring, and pulling images straight from a vendor repository into production do not enforce image validation or scanning.

Community Discussion

No comments yet. Be the first to start the discussion!