Professional Cloud Security EngineerManaging operationsEasy
A development team is deploying a new containerized application to Google Kubernetes Engine (GKE). They need to ensure that the container images used in their deployments are free from known vulnerabilities and meet organizational security policies *before* being deployed to production. Which Google Cloud service should they integrate into their CI/CD pipeline to achieve this?
- AWeb Security Scanner
- BSecurity Health Analytics
- CArtifact Analysis
- DContainer Threat Detection
Show answer & explanationAnswer & explanation
Correct answer: C. Artifact Analysis
Artifact Analysis (specifically its Vulnerability Scanning feature) is designed to scan container images stored in Container Registry or Artifact Registry for known vulnerabilities and provide policy enforcement capabilities during the build and deployment process. This allows issues to be caught before production deployment.
Why the other options are wrong
- A. Web Security Scanner is for identifying vulnerabilities in web applications (e.g., XSS, SQLi), not for scanning container images.
- B. Security Health Analytics (SHA) focuses on misconfigurations and compliance of Google Cloud resources, not scanning container images for vulnerabilities.
- D. Container Threat Detection (CTD) identifies runtime threats in GKE clusters, such as suspicious processes or library loading, *after* deployment, not pre-deployment image scanning.
Artifact Analysis for Vulnerability Scanning
Artifact Analysis is a service that provides metadata management and vulnerability scanning for software artifacts, including container images, stored in Google Cloud's registries.
- Scans container images for known vulnerabilities (CVEs)
- Integrates into CI/CD pipelines
- Supports policy enforcement before deployment
Memory trick: Analyze the Artifact before it ships!