Q: 1
[Governance, Risk, and Compliance (GRC)]
A security engineer is assisting a DevOps team that has the following requirements for container
images:
Ensure container images are hashed and use version controls.
Ensure container images are up to date and scanned for vulnerabilities.
Which of the following should the security engineer do to meet these requirements?
Options
Discussion
I don’t think it’s C. B fits because adding security and quality checks to the CI/CD pipeline is how you actually get hashing, version control, and vulnerability scans done before deploying containers. C is more about ongoing monitoring.
B
If the requirement was just about auditing changes after deploy, would C be better?
Be respectful. No spam.