CompTIA SecurityX (CAS-005)Security EngineeringMedium

A security architect is evaluating a new cloud-native application for deployment. The application relies heavily on containerized microservices orchestrated by Kubernetes. To ensure the integrity and authenticity of container images used in production, the architect wants to implement a mechanism that verifies the digital signature of each image before it is allowed to run. Which of the following best describes this security control?

  1. ARuntime Application Self-Protection (RASP)
  2. BContainer Image Signing and Verification
  3. CDynamic Application Security Testing (DAST)
  4. DWeb Application Firewall (WAF)
Show answer & explanation

Correct answer: B. Container Image Signing and Verification

Container image signing and verification ensures that container images come from a trusted source and have not been tampered with since they were signed. This is a critical integrity and authenticity control for containerized environments, preventing the deployment of malicious or compromised images.

Why the other options are wrong

  • A. RASP protects applications during runtime by detecting and blocking attacks, but it doesn't verify the integrity of container images before deployment.
  • C. DAST tests applications in their running state to find vulnerabilities, which is different from verifying the integrity of the container image itself.
  • D. A WAF protects web applications from common attacks at the network edge but does not verify the integrity or authenticity of container images.

Container Image Signing

The process of cryptographically signing a container image to assert its origin and ensure its integrity, allowing for verification that the image has not been tampered with.

  • Verifies image origin (authenticity)
  • Ensures image integrity (no tampering)
  • Uses digital signatures
  • Crucial for supply chain security in containers

Memory trick: Sign your images, trust your code.

More Security Engineering questions