A DevOps team builds Linux container images in a CI/CD pipeline and pushes them to a private registry. Security wants to catch vulnerable base-image packages and application dependencies before images reach production. Which vulnerability scanning method best addresses risk inherited from the container layer?
Select an answer to reveal the explanation.
Short Explanation
Think of a container image like a frozen pizza: if the crust is bad, baking it won't save it. You need to scan the image before it ships, because the vulnerable base layer travels with every deployment. Don't confuse that with checking the running app or the host.
Full Explanation
Container image scanning is the appropriate method because a container's security posture is assembled at build time from the base image, added layers, and installed packages. Scanning the image artifact in CI/CD reveals known vulnerabilities in those inherited components before the image is promoted to production, allowing the pipeline to fail or quarantine risky builds. Dynamic application security testing evaluates an already running application through its external interface, so it cannot reveal vulnerable packages inside an unstarted image layer. A network vulnerability scan of the container host examines exposed services on the underlying system, not the contents of the image registry artifact. Software composition analysis focuses on declared dependencies in source or lock files, which may miss the final packaged libraries present in the base image and installed system packages. Exam caveat: CS0-004 expects you to match the scanning artifact to the control point, not choose the broadest-sounding scan. Operational check: integrate an image scanner into the pipeline, record remediation owners, and block promotion when the base image or final image contains a critical CVE.