During a migration to microservices, a healthcare provider plans to package each workload as a container and deploy them through a CI/CD pipeline onto an on-premises Kubernetes cluster. The chief security architect must minimize the likelihood that vulnerable or malicious code reaches production while still allowing rapid deployments. Which action represents the MOST effective security practice for this goal?
Implement automated container image scanning in the CI/CD pipeline
Use the 'latest' tag for all production container images
Run containers with root privileges to ensure application functionality
Share the host kernel across all container environments to maximize efficiency
Container image scanning is the most effective security practice because it detects vulnerabilities, malicious code, and misconfigurations in container images before deployment. This proactive approach prevents vulnerable or compromised containers from entering the production environment.
Sharing the host kernel actually introduces security risks as containers have less isolation than virtual machines. Running containers as root violates the principle of least privilege and increases the attack surface. Using the latest tag for production images is risky because 'latest' is mutable and can lead to unpredictable deployments with potential security vulnerabilities.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is a CI/CD pipeline in the context of containerization?
Open an interactive chat with Bash
Why is container image scanning important for security?
Open an interactive chat with Bash
What does sharing the host kernel in container environments mean, and why is it risky?
Open an interactive chat with Bash
ISC2 CISSP
Security Architecture and Engineering
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .