Microsoft Certified: Azure Security Engineer AssociateImplement platform protectionMedium

An organization is deploying containerized applications to Azure Container Registry (ACR). Before deploying any container image to production, they need to ensure that the images are free of known vulnerabilities. The security team requires automated scanning of all new and existing images in ACR for security flaws and wants to receive alerts for critical vulnerabilities. Which Azure service should be integrated with ACR to meet this requirement?

  1. AAzure Monitor Container Insights
  2. BAzure Security Center (now Microsoft Defender for Cloud)
  3. CAzure Key Vault
  4. DAzure Policy
Show answer & explanation

Correct answer: B. Azure Security Center (now Microsoft Defender for Cloud)

Microsoft Defender for Cloud (formerly Azure Security Center) includes capabilities for scanning container images in Azure Container Registry for vulnerabilities. It provides continuous assessment, identifies vulnerabilities, and generates security recommendations and alerts based on the scan results.

Why the other options are wrong

  • A. Azure Monitor Container Insights monitors the performance and health of containerized applications, but it does not perform vulnerability scanning of images.
  • C. Azure Key Vault securely stores cryptographic keys and secrets; it is not involved in container image vulnerability scanning.
  • D. Azure Policy enforces organizational standards but doesn't perform the actual vulnerability scanning of container images.

Microsoft Defender for Containers (ACR)

Microsoft Defender for Containers (part of Defender for Cloud) provides vulnerability scanning for images stored in Azure Container Registry, offering continuous assessment and threat protection.

  • Scans images for vulnerabilities upon push and continuously.
  • Integrates with Qualys for vulnerability assessment.
  • Generates security recommendations and alerts.
  • Protects images in ACR, running AKS clusters, and Azure Container Instances.

Memory trick: To defend my containers, I need a 'Defender' to scan their images.

More Implement platform protection questions