Certified Cloud Security Professional (CCSP)Cloud Platform and Infrastructure SecurityMedium

A cloud security architect is designing a secure CI/CD pipeline for containerized applications. A critical requirement is to ensure that container images used in deployment are free from known vulnerabilities and meet organizational compliance standards before being pushed to the container registry. Which security control should be integrated early in the CI/CD pipeline to address this requirement?

  1. ARuntime Application Self-Protection (RASP)
  2. BNetwork Segmentation
  3. CWeb Application Firewall (WAF)
  4. DContainer Image Scanning
Show answer & explanation

Correct answer: D. Container Image Scanning

Container image scanning tools analyze container images for known vulnerabilities, misconfigurations, and compliance violations, providing a critical security gate before deployment.

Why the other options are wrong

  • A. RASP protects applications at runtime but not during the image build/push phase.
  • B. Network segmentation controls traffic flow between containers at runtime, not image vulnerabilities.
  • C. A WAF protects web applications from attacks at the network edge but does not scan container images.

Container Image Scanning

The automated process of analyzing container images for known vulnerabilities, misconfigurations, and policy violations, typically integrated into CI/CD pipelines.

  • Identifies security risks before containers are deployed.
  • Leverages vulnerability databases (CVEs).
  • Helps enforce security policies and compliance standards.

Memory trick: Before you put your container on the boat (registry) and sail it (deploy), SCAN it for holes! Make sure it's seaworthy and won't sink your operations.

More Cloud Platform and Infrastructure Security questions