Kubernetes and Cloud Native Associate (KCNA)Cloud Native DeliveryMedium

A financial institution is deploying a critical banking application on Kubernetes. Due to strict regulatory compliance and security policies, they need to ensure that only approved container images from trusted sources can be used in their deployments. Which Cloud Native component is essential for centralizing and enforcing this policy?

  1. AA Kubernetes Ingress controller
  2. BA private container registry
  3. CA Helm chart repository
  4. DA public Docker Hub repository
Show answer & explanation

Correct answer: B. A private container registry

A private container registry allows organizations to store, manage, and secure their own approved container images. This provides granular control over image access, scanning, and provenance, which is crucial for compliance and security in regulated environments.

Why the other options are wrong

  • A. An Ingress controller manages external access to services within the cluster.
  • C. A Helm chart repository stores application packages, not container images.
  • D. Public registries lack control and security required for sensitive applications.

Private Container Registry

A centralized, secure repository for storing and managing container images within an organization, offering enhanced control, security, and compliance over image provenance and access.

  • Provides granular access control for sensitive images.
  • Enables vulnerability scanning and policy enforcement.
  • Supports air-gapped or restricted network environments.

Memory trick: Your private registry is the vault for approved images.

More Cloud Native Delivery questions