Google Cloud Digital LeaderSecurity and operations with Google CloudMedium

A global e-commerce company uses Google Kubernetes Engine (GKE) for its microservices. They want to ensure that all container images deployed to GKE are free from known vulnerabilities before they are run in production. Which Google Cloud service helps them achieve this pre-deployment vulnerability scanning?

  1. AContainer Analysis
  2. BArtifact Registry
  3. CCloud Security Command Center
  4. DContainer Registry
Show answer & explanation

Correct answer: A. Container Analysis

Container Analysis scans container images stored in Artifact Registry or Container Registry for known vulnerabilities and provides detailed reports, enabling pre-deployment security checks.

Why the other options are wrong

  • B. Artifact Registry stores and manages container images and other artifacts, but does not perform vulnerability scanning itself.
  • C. Cloud Security Command Center is a centralized security management and data risk platform, it doesn't directly scan container images.
  • D. Container Registry is a deprecated service for storing container images; Artifact Registry is its successor, neither perform scanning directly.

Container Analysis

Container Analysis is a service that scans container images for known vulnerabilities, provides metadata about images, and helps ensure the security of your containerized applications.

  • Scans images in Artifact Registry/Container Registry.
  • Identifies OS package and language-specific vulnerabilities.
  • Integrates with CI/CD pipelines.
  • Provides build provenance and metadata.

Memory trick: Analyze containers before they deploy and fly.

More Security and operations with Google Cloud questions