You need to add a vulnerability scan step for built container images in Cloud Build with minimal disruption and make results available to your deployment pipeline. What should you do?
Choose an answer
Tap an option to check your answer.
Correct answer: Enable the Container Scanning API in Artifact Registry and scan the built container images..
Why this is the answer
Enabling the Container Scanning API in Artifact Registry directly integrates vulnerability scanning into your existing Google Cloud build and deployment workflow. Artifact Registry is Google Cloud's fully managed artifact management service, and its built-in scanning capabilities provide a native, low-disruption way to identify vulnerabilities in your container images. The scan results are then readily available within the Google Cloud ecosystem, making them accessible to subsequent deployment pipeline steps. Binary Authorization is for enforcing deployment policies based on attestations, not for performing the initial vulnerability scan itself. Uploading images to Docker Hub introduces an external dependency and potential security concerns for private images, and doesn't integrate natively with Cloud Build for scanning. Adding Artifact Registry to an Aqua Security instance is a valid approach for advanced security needs, but it involves integrating a third-party tool, which is not the minimal disruption solution requested when a native option exists.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed