Professional Cloud ArchitectDesign for security and complianceMedium

A global software company maintains a large repository of container images in Artifact Registry. They need to ensure that all container images deployed to production environments are free from known vulnerabilities and comply with internal security policies before deployment. They also need to automate this scanning process as part of their CI/CD pipeline. Which Google Cloud service should be integrated into their pipeline to achieve this?

  1. ACloud Logging
  2. BCloud Build
  3. CContainer Analysis API
  4. DBinary Authorization
Show answer & explanation

Correct answer: C. Container Analysis API

The Container Analysis API is specifically designed to scan container images for known vulnerabilities and provide metadata about the images, which is exactly what's needed for compliance and security checks in a CI/CD pipeline. Cloud Build is for building and deploying, not scanning. Binary Authorization enforces deployment policies but relies on information from Container Analysis. Cloud Logging monitors logs, not scans images.

Why the other options are wrong

  • A. Cloud Logging is a service for collecting, storing, and analyzing logs; it is not used for vulnerability scanning of container images.
  • B. Cloud Build is a CI/CD service for building, testing, and deploying, but it does not inherently perform vulnerability scanning of container images; it orchestrates the process.
  • D. Binary Authorization enforces deployment policies by checking for attestation (e.g., from vulnerability scans or build approvals) but does not perform the vulnerability scanning itself; it consumes the results.

Container Analysis API

A Google Cloud service that provides vulnerability scanning, software bill of materials (SBOM) generation, and policy enforcement for container images and other artifacts.

  • Automatically scans images in Artifact Registry.
  • Identifies known vulnerabilities (CVEs).
  • Integrates with CI/CD pipelines for automated security checks.

Memory trick: Analyze the Container, Scan for Flaws, Before Deployment, Obey the Laws.

More Design for security and compliance questions