Professional Cloud Security EngineerManaging operationsEasy
An organization is deploying a new containerized application on Google Kubernetes Engine (GKE). They need to monitor the runtime behavior of their containers for suspicious activities, such as unexpected process execution, binary tampering, or attempts to access sensitive files. They require a fully managed service that provides real-time threat detection within the GKE cluster. Which Google Cloud service should they enable?
- AContainer Threat Detection (CTD)
- BSecurity Health Analytics (SHA)
- CCloud Monitoring with GKE metrics
- DEvent Threat Detection (ETD)
Show answer & explanationAnswer & explanation
Correct answer: A. Container Threat Detection (CTD)
Container Threat Detection (CTD) is specifically designed to detect runtime threats within GKE clusters, including suspicious process execution, binary tampering, and access to sensitive data, by analyzing signals from the cluster and reporting findings to Security Command Center.
Why the other options are wrong
- B. Security Health Analytics (SHA) identifies misconfigurations and vulnerabilities at rest, not runtime threats in containers.
- C. Cloud Monitoring provides operational metrics and logs, but does not perform advanced threat detection on container runtime behavior.
- D. Event Threat Detection (ETD) analyzes Cloud Logging data for general threats, not specifically for container runtime behavior.
Container Threat Detection (CTD)
A Google Cloud service that provides runtime threat detection for Google Kubernetes Engine (GKE) clusters, identifying suspicious activities like reverse shells, cryptomining, and binary tampering, and reporting findings to Security Command Center.
- Monitors GKE clusters for runtime threats.
- Detects suspicious container behavior (e.g., process execution, file access).
- Generates findings in Security Command Center.
- A fully managed service for container security.
Memory trick: CTD is your 'Container Threat Detector', watching your 'ships' for 'pirates' at sea.