Company builds Docker images from various open-source OS bases and must scan published images for CVEs without slowing developers, preferring managed services. What should you enable?
Choose an answer
Tap an option to check your answer.
Correct answer: Enable the Vulnerability scanning setting in the Container Registry..
Why this is the answer
Enabling vulnerability scanning in Container Registry (now Artifact Registry) is the most direct and efficient solution. This managed service automatically scans images for known vulnerabilities upon push, providing continuous security without developer intervention. It directly addresses the requirement for scanning published images and preferring managed services. Creating a Cloud Function for code check-in scanning is incorrect because the requirement is to scan published images, not source code, and it would require custom development and maintenance. Disallowing non-commercially supported base images is a policy decision, not a technical solution for scanning existing images, and doesn't meet the "scan published images" requirement. Using Cloud Monitoring to review Cloud Build output is an indirect and manual approach that doesn't provide automated vulnerability scanning of the final image, nor does it leverage a dedicated managed scanning service.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed