You plan to use Azure DevOps to build and deploy an application to a Kubernetes cluster. To scan the container image for vulnerabilities before deployment to the cluster, which solution should you include?
Choose an answer
Tap an option to check your answer.
Correct answer: Microsoft Defender for Containers.
Why this is the answer
Microsoft Defender for Containers is the correct solution because it provides cloud-native security for containers, including vulnerability scanning of images in registries and at runtime. This directly addresses the requirement to scan container images for vulnerabilities before deployment to a Kubernetes cluster. Microsoft Defender for App Service protects Azure App Service plans, not container images or Kubernetes clusters. Microsoft Defender for DevOps integrates security into the CI/CD pipeline but doesn't perform the actual container image vulnerability scanning itself; it orchestrates and reports on findings from other tools like Defender for Containers. Microsoft Defender for Storage monitors Azure Storage accounts for suspicious activity, which is unrelated to container image scanning.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed