Your subscription contains an Azure Container Registry named Registry1 and Microsoft Defender for Cloud is enabled. You uploaded container images to Registry1 but vulnerability scans did not run. What should you do to ensure images are scanned for vulnerabilities when uploaded?
Choose an answer
Tap an option to check your answer.
Correct answer: From the Azure portal, modify the Pricing tier settings..
Why this is the answer
To enable vulnerability scanning for container images in Azure Container Registry (ACR) with Microsoft Defender for Cloud, you must ensure the ACR's pricing tier is set to Premium or Standard. The Basic tier does not support Defender for Cloud integration for vulnerability assessments. Modifying the pricing tier in the Azure portal will enable this functionality. Locking container images (via Azure CLI) prevents deletion but doesn't initiate scans. Uploading images with AzCopy or pushing them with Docker are methods of getting images into the registry, but they don't configure the scanning service itself. The core issue is the ACR's capability to integrate with Defender for Cloud, which is tied to its pricing tier.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed