Soru

Zorluk: KolayVulnerability Scanning, Container Security, and Threat Detection

Match each Google Cloud security service on the left to its primary functional capability in container security and threat detection on the right.

  • Container AnalysisPerforms static vulnerability scanning on container images stored in Artifact Registry.
  • Binary AuthorizationEnforces signature-based deployment policies to prevent unauthorized container images from running on GKE.
  • Event Threat DetectionAnalyzes Cloud Logging streams within Security Command Center to detect near-real-time security threats.

Cevap

Container Analysis pairs with scanning container images for vulnerabilities in Artifact Registry; Binary Authorization pairs with enforcing signature-based image deployment policies on GKE; Event Threat Detection pairs with analyzing log streams in Security Command Center to identify threats.
Container Analysis provides vulnerability scanning for container images stored in registries. Binary Authorization ensures only verified, signed images are deployed to GKE clusters. Event Threat Detection processes log streams to identify active security threats across GCP resources.

Adım Adım Çözüm

1
Identify the primary role of Container Analysis.
Container Analysis scans container images stored in Artifact Registry for vulnerability CVEs.
Container Analysis provides static vulnerability scanning for stored artifacts.
2
Identify the primary role of Binary Authorization.
Binary Authorization verifies cryptographic signatures prior to container deployment on GKE.
Binary Authorization enforces deploy-time security policies based on attestations.
3
Identify the primary role of Event Threat Detection.
Event Threat Detection analyzes log streams within Security Command Center to detect threat indicators.
Event Threat Detection provides real-time analysis of audit and system logs for threat activity.

Anahtar Kavram

Vulnerability Scanning, Container Security, and Threat Detection
Bu soruyu puanla