Cisco CCNP Security Core (SCOR) 350-701Cloud SecurityMedium

An organization is deploying a new containerized application using Kubernetes in a public cloud. The security team needs to ensure that containers are scanned for vulnerabilities before deployment and that only approved images from a trusted registry are used. Which cloud security tool or practice is most effective for achieving this goal?

  1. AImplementing a Cloud Native Application Protection Platform (CNAPP)
  2. BUtilizing a Cloud Access Security Broker (CASB)
  3. CConfiguring a Security Information and Event Management (SIEM) system
  4. DDeploying a Web Application Firewall (WAF) at the ingress
Show answer & explanation

Correct answer: A. Implementing a Cloud Native Application Protection Platform (CNAPP)

A CNAPP integrates various security capabilities, including container image scanning, supply chain security, and continuous posture management, making it highly effective for securing containerized applications and enforcing approved image usage.

Why the other options are wrong

  • B. CASBs focus on SaaS/PaaS security, data governance, and threat protection, not container image scanning.
  • C. SIEMs collect and analyze logs, primarily for detection, not for pre-deployment image scanning and enforcement.
  • D. WAFs protect web applications from network attacks at runtime, not container images before deployment.

Cloud Native Application Protection Platform (CNAPP)

A unified security platform that provides a broad set of security capabilities for cloud-native applications across the entire lifecycle, from development to runtime.

  • Integrates multiple security functions (CSPM, CIEM, CWPP, container security).
  • Covers development (shift-left), build, deploy, and runtime phases.
  • Essential for securing containerized and serverless environments.

Memory trick: For cloud-native apps, CNAPP is the all-in-one protector.

More Cloud Security questions