Microsoft Certified: Azure Security Engineer AssociateImplement platform protectionMedium
A development team is using Azure DevOps to build and deploy containerized applications to Azure Kubernetes Service (AKS). They need to ensure that container images stored in their Azure Container Registry (ACR) are regularly scanned for vulnerabilities before deployment. Which Azure service should be integrated with ACR to provide continuous vulnerability assessment for container images?
- AAzure Advisor
- BMicrosoft Defender for Cloud
- CAzure Policy
- DAzure Monitor
Show answer & explanationAnswer & explanation
Correct answer: B. Microsoft Defender for Cloud
Microsoft Defender for Cloud (specifically the Defender for Containers plan) provides vulnerability assessment for images stored in Azure Container Registry. It scans images upon push and provides continuous assessment, integrating directly with ACR.
Why the other options are wrong
- A. Azure Advisor provides personalized recommendations for best practices, but not continuous vulnerability scanning of container images.
- C. Azure Policy enforces organizational standards and compliance, but doesn't perform the actual vulnerability scanning.
- D. Azure Monitor collects and analyzes telemetry, but doesn't perform vulnerability scanning of container images.
Defender for Cloud for ACR
Microsoft Defender for Cloud, with its Defender for Containers plan, provides vulnerability assessment and threat protection for container images stored in Azure Container Registry.
- Scans images for vulnerabilities upon push to ACR.
- Provides continuous assessment of images.
- Integrates with Azure Container Registry.
- Offers security recommendations and alerts.
Memory trick: Defender for Cloud: Your image's security scanner in the registry.