CompTIA Security+ (SY0-701)Security ArchitectureHard

A security team integrates a step into the CI/CD pipeline that inspects container images for known CVEs in installed packages before allowing them to be pushed to the production registry. Which security practice does this represent?

  1. ADynamic application security testing
  2. BNetwork traffic analysis
  3. CRuntime application self-protection
  4. DContainer image vulnerability scanning
Show answer & explanation

Correct answer: D. Container image vulnerability scanning

Scanning container images for known vulnerabilities (CVEs) in their layers and packages before deployment is a shift-left security practice specific to container/image supply chain security.

Why the other options are wrong

  • A. DAST tests a running application from the outside for vulnerabilities, not static container image contents.
  • B. Network traffic analysis inspects live traffic patterns, unrelated to static image inspection.
  • C. RASP protects applications at runtime from within the running process, not during pre-deployment image builds.

Container Image Scanning

A CI/CD pipeline security control that inspects container image layers and installed packages for known vulnerabilities (CVEs) before deployment.

  • Shift-left security practice integrated into build pipelines
  • Often blocks promotion of images above a risk threshold
  • Complements image signing and least-privilege runtime configs

Memory trick: Scan the box before you ship it.

More Security Architecture questions