🔥 3-day streak
Cisco CCNP Security SCOR (350-701)20 / 146
Question 20 of 146

A DevSecOps team builds Docker images that are pushed to a private registry before deployment into a Kubernetes cluster. Recently, a production workload was found running an image containing a critical CVE in a bundled OS library. The security architect wants to prevent vulnerable images from ever reaching the cluster while keeping the CI/CD pipeline automated. Which control best addresses this requirement?

Reviewed for accuracy · Report an issueNext question