Google Professional Cloud DevOps Engineer exam dumps

Google Professional Cloud DevOps Engineer practice question 87 of 268

Professional Cloud DevOps Engineer. Associate level, Google Cloud. Free question with the correct answer and a full explanation.

Google Professional Cloud DevOps Engineer Question 87

Select 3Google Cloud Platform

Your organization is using Artifact Registry to store container images. As part of your security strategy, you want to ensure that all images are regularly scanned for vulnerabilities. What steps must you take to enable vulnerability analysis for your container images in Artifact Registry?

  1. A

    Ensure that the Artifact Registry repository is configured with the vulnerability scanning feature enabled.

  2. B

    Grant the necessary IAM permissions, such as roles/containeranalysis.occurrences.viewer, to appropriate users or services.

  3. C

    Enable the Container Analysis API for your project.

  4. D

    Manually trigger vulnerability scans for each image after they are pushed to the registry.

  5. E

    Update the Dockerfile of each image to include a specific security scanning tool.

Show answer and explanation

Correct answers: A, B, C

Explanation

To enable vulnerability analysis in Artifact Registry, you need to configure the repository to allow vulnerability scanning, ensure proper IAM permissions are granted, and enable the Container Analysis API. Once configured, Artifact Registry automatically scans images upon push, and additional modifications to Dockerfiles or manual scans are not required.

  • A. Correct.

    Correct. Enabling vulnerability scanning in your Artifact Registry repository is required to analyze images for vulnerabilities.

  • B. Correct.

    Correct. Granting IAM permissions like roles/containeranalysis.occurrences.viewer is necessary for viewing and managing vulnerability findings.

  • C. Correct.

    Correct. The Container Analysis API must be enabled to support vulnerability scanning and reporting in Artifact Registry.

  • D. Incorrect.

    Incorrect. Scans are triggered automatically when images are pushed to a repository with vulnerability scanning enabled, so manual triggering is unnecessary.

  • E. Incorrect.

    Incorrect. There is no need to modify Dockerfiles to include security tools because the scanning is performed by Artifact Registry's built-in functionality.

Timed practice exam

Take a Google Professional Cloud DevOps Engineer practice test under exam conditions

60 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam