Professional Cloud Security EngineerManaging operationsHard
A gaming company uses Google Kubernetes Engine (GKE) for its online multiplayer games. They need to ensure that container images deployed to production are free of known vulnerabilities and that their GKE clusters are not running any vulnerable software. They also need to detect suspicious activities within running containers, such as reverse shell attempts or crypto-mining processes. Which two Google Cloud services, when used together, provide the most comprehensive solution for these requirements?
- ASecurity Health Analytics and Event Threat Detection.
- BWeb Security Scanner and Policy Intelligence.
- CCloud Monitoring and Cloud Logging.
- DArtifact Analysis and Container Threat Detection.
Show answer & explanationAnswer & explanation
Correct answer: D. Artifact Analysis and Container Threat Detection.
Artifact Analysis scans container images for known vulnerabilities before deployment. Container Threat Detection (CTD) then monitors running GKE clusters for suspicious activities within containers, such as reverse shells or crypto-mining, providing comprehensive security for containerized workloads.
Why the other options are wrong
- A. Security Health Analytics focuses on misconfigurations and compliance, not container image scanning or runtime container threat detection. Event Threat Detection is for general Google Cloud threats, not specific to container runtime anomalies.
- B. Web Security Scanner focuses on web application vulnerabilities, and Policy Intelligence helps with IAM and resource policies; neither addresses container image scanning or runtime container threats.
- C. Cloud Monitoring and Cloud Logging are foundational for observability but do not provide specialized vulnerability scanning for container images or runtime threat detection for containers.
Container Security Duo: Artifact Analysis & CTD
Artifact Analysis scans container images for vulnerabilities (pre-deployment), while Container Threat Detection (CTD) monitors running GKE containers for runtime threats and suspicious activity (post-deployment).
- Artifact Analysis: Image vulnerability scanning.
- Container Threat Detection: Runtime container threat monitoring.
- Together provide end-to-end container security.
- Integrated with Security Command Center.
Memory trick: Analyze before you deploy, detect threats as they play.