Professional Cloud ArchitectDesign for security and complianceMedium

A software development company uses Artifact Registry to store their container images and Maven artifacts. They need to ensure that all artifacts pushed to the registry are scanned for known vulnerabilities before they can be deployed to production environments. This is a critical step in their secure software supply chain strategy. Which Google Cloud service integrates with Artifact Registry to automatically perform vulnerability scanning on container images?

  1. ABinary Authorization
  2. BContainer Analysis API
  3. CSecurity Command Center
  4. DCloud Build
Show answer & explanation

Correct answer: B. Container Analysis API

Container Analysis API (often referred to as Container Analysis) automatically scans container images stored in Artifact Registry or Container Registry for known vulnerabilities and provides metadata about these vulnerabilities.

Why the other options are wrong

  • A. Binary Authorization enforces deployment policies (e.g., only allowing signed images), but it relies on services like Container Analysis for vulnerability assessment, it doesn't perform the scan itself.
  • C. Security Command Center aggregates security findings but does not perform the direct vulnerability scanning of container images itself; it displays findings from services like Container Analysis.
  • D. Cloud Build is a CI/CD service for building artifacts, but it doesn't inherently perform vulnerability scanning on the built images.

Container Analysis API (for Artifact Registry)

A Google Cloud service that automatically scans container images stored in Artifact Registry and Container Registry for known vulnerabilities, providing security insights.

  • Integrates directly with Artifact Registry and Container Registry.
  • Identifies CVEs and other security findings in image layers.
  • Provides metadata and insights for policy enforcement (e.g., with Binary Authorization).

Memory trick: Artifacts Analyzed, Authorization Assured.

More Design for security and compliance questions