Certified Cloud Security Professional (CCSP)Cloud Platform and Infrastructure SecurityMedium
A development team is deploying a new microservices-based application using containers in a public cloud. The security architect is concerned about potential vulnerabilities in the container images themselves, as well as runtime threats. Which of the following security practices should the team prioritize to address these concerns effectively?
- AScanning container images for vulnerabilities before deployment and enforcing runtime security policies.
- BUtilizing an advanced Web Application Firewall (WAF) to protect containerized services.
- CEncrypting all data stored within container volumes at rest and in transit.
- DImplementing a robust patch management policy for the underlying host OS.
Show answer & explanationAnswer & explanation
Correct answer: A. Scanning container images for vulnerabilities before deployment and enforcing runtime security policies.
To address vulnerabilities in container images and runtime threats, it is crucial to scan images for known vulnerabilities *before* deployment (shifting left) and then enforce runtime security policies to monitor and protect containers during execution. This covers both static and dynamic aspects of container security.
Why the other options are wrong
- B. A WAF protects web applications from HTTP-based attacks but does not address vulnerabilities within the container images or general runtime threats for all types of containerized services.
- C. Encrypting data is vital for data confidentiality and integrity but does not directly prevent vulnerabilities in the container image or mitigate runtime threats to the container's execution environment.
- D. Patching the host OS is important for overall infrastructure security but doesn't directly address vulnerabilities within the container images or runtime threats specific to container processes.
Container Security Best Practices
A set of practices to secure containerized applications throughout their lifecycle, from image creation to runtime execution.
- Scan images for vulnerabilities pre-deployment.
- Enforce runtime policies for container behavior.
- Use minimal base images.
Memory trick: Scan your boxes before they run, then watch them closely under the sun.