Google Cloud Digital LeaderSecurity and operations with Google CloudMedium

A software development company is deploying microservices on Google Kubernetes Engine (GKE). They need to ensure that container images used in their deployments are free from known vulnerabilities before they are deployed to production. Which Google Cloud security product can help them automate the scanning of container images for vulnerabilities?

  1. AArtifact Registry
  2. BContainer Registry
  3. CBinary Authorization
  4. DContainer Analysis
Show answer & explanation

Correct answer: D. Container Analysis

Container Analysis is a service that provides metadata about your container images, including vulnerability scanning. It integrates with Container Registry and Artifact Registry to automatically scan images for known vulnerabilities and provide security insights.

Why the other options are wrong

  • A. Artifact Registry is a universal package manager that stores various artifact types, including container images, but it relies on Container Analysis for vulnerability scanning.
  • B. Container Registry is a private Docker image registry, but it doesn't inherently perform vulnerability scanning itself.
  • C. Binary Authorization enforces deployment policies by requiring attestations for images, but it doesn't perform the vulnerability scanning itself.

Container Analysis

Container Analysis provides metadata about your container images, including vulnerability scanning, build provenance, and other security insights.

  • Integrates with Container Registry and Artifact Registry.
  • Automatically scans images for known vulnerabilities.
  • Provides a centralized view of security insights for containers.

Memory trick: Registry Analyzes Binaries for Safe Deployment.

More Security and operations with Google Cloud questions