nerdexam
Microsoft

SC-100 · Question #36

You are designing the security standards for containerized applications onboarded to Azure. You are evaluating the use of Microsoft Defender for Containers. In which two environments can you use…

The correct answer is A. Linux containers deployed to Azure Container Registry B. Linux containers deployed to Azure Kubernetes Service (AKS). Microsoft Defender for Containers provides vulnerability scanning for Linux containers in two key environments: Azure Container Registry (A) and Azure Kubernetes Service (B). For ACR, Defender for Containers scans Linux container images upon push and on a schedule to identify…

Design security solutions for infrastructure

Question

You are designing the security standards for containerized applications onboarded to Azure. You are evaluating the use of Microsoft Defender for Containers. In which two environments can you use Defender for Containers to scan for known vulnerabilities? Each correct answer presents a complete solution. NOTE: Each correct selection is worth one point.

Options

  • ALinux containers deployed to Azure Container Registry
  • BLinux containers deployed to Azure Kubernetes Service (AKS)
  • CWindows containers deployed to Azure Container Registry
  • DWindows containers deployed to Azure Kubernetes Service (AKS)
  • ELinux containers deployed to Azure Container Instances

How the community answered

(42 responses)
  • A
    86% (36)
  • C
    2% (1)
  • D
    7% (3)
  • E
    5% (2)

Explanation

Microsoft Defender for Containers provides vulnerability scanning for Linux containers in two key environments: Azure Container Registry (A) and Azure Kubernetes Service (B). For ACR, Defender for Containers scans Linux container images upon push and on a schedule to identify known CVEs. For AKS, it provides both runtime threat protection and vulnerability assessment for Linux-based workloads. Windows container vulnerability scanning is not supported by Defender for Containers in either ACR (C) or AKS (D) - this is a documented limitation as the scanning capabilities are focused on Linux container images. Azure Container Instances (E) is also not a supported environment for Defender for Containers vulnerability scanning; Defender for Containers is scoped to ACR, AKS, and Arc-enabled Kubernetes clusters.

Topics

#Microsoft Defender for Containers#Container Security#Vulnerability Management#Azure Container Services

Community Discussion

No community discussion yet for this question.

Full SC-100 Practice