Microsoft Certified: Azure Security Engineer AssociateImplement platform protectionMedium

A development team is using Azure DevOps to build and deploy containerized applications to Azure Kubernetes Service (AKS). To ensure the integrity and security of the deployed images, the security team requires that all container images stored in Azure Container Registry (ACR) must be regularly scanned for vulnerabilities. If a critical vulnerability is found, the deployment pipeline should be blocked. Which Azure service integration provides this capability?

  1. AMicrosoft Defender for Cloud (formerly Azure Security Center) integration with ACR
  2. BAzure Monitor integration with ACR
  3. CAzure Advisor recommendations for ACR
  4. DAzure Policy for ACR retention
Show answer & explanation

Correct answer: A. Microsoft Defender for Cloud (formerly Azure Security Center) integration with ACR

Microsoft Defender for Cloud (formerly Azure Security Center) provides integrated vulnerability scanning for images in Azure Container Registry. When enabled, it automatically scans images upon push and on an ongoing basis, identifying vulnerabilities. This integration can then be used to automate blocking deployments based on scan results.

Why the other options are wrong

  • B. Azure Monitor collects logs and metrics, but doesn't perform vulnerability scanning for container images.
  • C. Azure Advisor provides recommendations for cost, performance, reliability, and security, but doesn't perform active vulnerability scanning or enforcement in pipelines.
  • D. Azure Policy for ACR retention manages the lifecycle of images (e.g., deleting old ones), not vulnerability scanning.

Defender for Cloud for ACR

Microsoft Defender for Cloud provides native vulnerability management for container images stored in Azure Container Registry, offering continuous scanning and actionable recommendations.

  • Automatic scanning of images upon push and continuously.
  • Identifies vulnerabilities in OS packages and application dependencies.
  • Integrates with Azure DevOps for 'shift-left' security in CI/CD pipelines.

Memory trick: Defender for Cloud scans your container images like a digital detective.

More Implement platform protection questions