Google Cloud Digital LeaderSecurity and operations with Google CloudMedium

A global e-commerce company uses Google Kubernetes Engine (GKE) for its microservices. They need to ensure that all container images deployed to production environments are free from known vulnerabilities and comply with internal security policies. Which Google Cloud service helps them automate this scanning and policy enforcement?

  1. AArtifact Registry
  2. BContainer Registry
  3. CCloud Build
  4. DContainer Analysis
Show answer & explanation

Correct answer: D. Container Analysis

Container Analysis provides vulnerability scanning, metadata management, and policy enforcement for container images, ensuring security compliance before deployment.

Why the other options are wrong

  • A. Artifact Registry is a universal package manager for various artifact types, including container images, but its core function is storage, not vulnerability analysis.
  • B. Container Registry stores and manages Docker images, but does not inherently provide automated vulnerability scanning or policy enforcement.
  • C. Cloud Build is a continuous integration service for building applications, not primarily for vulnerability scanning of images.

Container Analysis

Container Analysis is a service that provides vulnerability scanning, metadata management, and policy enforcement for container images stored in Container Registry or Artifact Registry.

  • Automatically scans images for known vulnerabilities.
  • Integrates with CI/CD pipelines to block deployments of vulnerable images.
  • Provides insights into image provenance and software bill of materials (SBOM).

Memory trick: Analyze containers to find hidden threats.

More Security and operations with Google Cloud questions