Kubernetes and Cloud Native Associate (KCNA)Cloud Native DeliveryEasy

A financial institution is deploying a critical banking application on Kubernetes. Due to strict compliance requirements and data residency laws, they cannot use public container registries. Which type of registry should they use to store their application images securely?

  1. AGoogle Container Registry
  2. BDocker Hub
  3. CPrivate Container Registry
  4. DQuay.io
Show answer & explanation

Correct answer: C. Private Container Registry

A private container registry allows organizations to host their container images within their own infrastructure or a dedicated, secure environment, ensuring compliance with strict security and data residency requirements.

Why the other options are wrong

  • A. Google Container Registry is a cloud-provider specific public/managed registry.
  • B. Docker Hub is a public registry with images accessible to a wide audience.
  • D. Quay.io is a public container registry for both public and private images, but often managed by a third-party.

Private Container Registry

A private container registry is a secure, isolated repository for storing and managing container images, typically used by organizations with specific security, compliance, or network requirements.

  • Offers enhanced security and access control.
  • Facilitates compliance with regulatory standards.
  • Can be self-hosted or managed by a cloud provider within a private context.

Memory trick: For banking, keep images in your own vault, not the public square.

More Cloud Native Delivery questions