CompTIA Security+ (SY0-701)Security ArchitectureHard
A security team integrates a step into the CI/CD pipeline that inspects container images for known CVEs in installed packages before allowing them to be pushed to the production registry. Which security practice does this represent?
- ADynamic application security testing
- BNetwork traffic analysis
- CRuntime application self-protection
- DContainer image vulnerability scanning
Show answer & explanationAnswer & explanation
Correct answer: D. Container image vulnerability scanning
Scanning container images for known vulnerabilities (CVEs) in their layers and packages before deployment is a shift-left security practice specific to container/image supply chain security.
Why the other options are wrong
- A. DAST tests a running application from the outside for vulnerabilities, not static container image contents.
- B. Network traffic analysis inspects live traffic patterns, unrelated to static image inspection.
- C. RASP protects applications at runtime from within the running process, not during pre-deployment image builds.
Container Image Scanning
A CI/CD pipeline security control that inspects container image layers and installed packages for known vulnerabilities (CVEs) before deployment.
- Shift-left security practice integrated into build pipelines
- Often blocks promotion of images above a risk threshold
- Complements image signing and least-privilege runtime configs
Memory trick: Scan the box before you ship it.