Kubernetes and Cloud Native Associate (KCNA)Cloud Native SecurityMedium
A company is adopting a DevSecOps approach and wants to integrate security scanning into their CI/CD pipeline for Kubernetes deployments. They need to scan container images for known vulnerabilities *before* they are pushed to a registry and *before* deployment. Which phase of the software supply chain would this type of scanning primarily fall under?
- ARuntime Security
- BSecrets Management
- CDeployment and Orchestration
- DBuild and Image Creation
Show answer & explanationAnswer & explanation
Correct answer: D. Build and Image Creation
Scanning container images for vulnerabilities before pushing them to a registry or deploying them is a critical step in the 'Build and Image Creation' phase of the software supply chain. This proactive approach helps identify and remediate issues early, shifting security left.
Why the other options are wrong
- A. Runtime security focuses on protecting applications while they are running in the cluster.
- B. Secrets management deals with handling sensitive data, not image vulnerability scanning.
- C. Deployment and orchestration involves managing the deployment of already built and (ideally) scanned images.
Shift-Left Security
The practice of integrating security measures and testing earlier in the software development lifecycle (SDLC) to identify and address vulnerabilities proactively.
- Reduces cost and effort of fixing security issues.
- Involves security testing in design, development, and build phases.
- Applies to code, dependencies, and container images.
Memory trick: Build secure, deploy secure, run secure.