2V0-71.23 exam dumps

2V0-71.23 practice question 352 of 355

VMware Certified Professional - Tanzu for Kubernetes Operations 2024. Associate level, VMware. Free question with the correct answer and a full explanation.

2V0-71.23 Question 352

Select 3

Your organization is using VMware Tanzu Kubernetes Grid (TKG) to manage containerized workloads. As part of your security policy, you need to ensure that container images with critical Common Vulnerabilities and Exposures (CVEs) are blocked from being deployed. Which actions should you take to implement this policy effectively using Tanzu’s image registry scanning capabilities?

  1. A

    Integrate VMware Tanzu with a container registry that supports image scanning for CVEs, such as Harbor.

  2. B

    Configure image policies in Tanzu Kubernetes Grid to block images flagged with critical CVEs during deployment.

  3. C

    Deploy a network policy to restrict access to the container registry for images with CVEs.

  4. D

    Enable automatic remediation of critical CVEs in the container registry to ensure all images are patched.

  5. E

    Set up notification policies in the container registry to alert administrators about newly identified critical CVEs.

Show answer and explanation

Correct answers: A, B, E

Explanation

To effectively block container images with critical CVEs in VMware Tanzu, you must integrate with a registry like Harbor that supports vulnerability scanning, configure image policies to enforce blocking based on CVE severity, and set up notifications to stay informed of new vulnerabilities. These steps provide a comprehensive approach to securing the container lifecycle.

  • A. Correct.

    Integrating VMware Tanzu with a container registry that supports image scanning, such as Harbor, is essential for identifying CVEs in container images. This step ensures that the registry can detect vulnerabilities in images before they are deployed.

  • B. Correct.

    Configuring image policies in Tanzu Kubernetes Grid allows you to block images flagged with critical CVEs, thereby preventing non-compliant images from being deployed into clusters.

  • C. Incorrect.

    Deploying a network policy to restrict access to the container registry does not directly address the need to scan for or block critical CVEs in images. This is unrelated to the registry scanning policies.

  • D. Incorrect.

    While enabling automatic remediation of CVEs is a useful feature, it is not always supported and does not guarantee that critical CVEs will be addressed before deployment. This is not a sufficient action by itself to block critical CVEs.

  • E. Correct.

    Setting up notification policies ensures that administrators are alerted about critical CVEs, enabling them to take corrective action. This is a complementary step in implementing an effective CVE management policy.

Timed practice exam

Take a 2V0-71.23 practice test under exam conditions

63 questions in 130 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam