問題文
A team wants to be sure that the artifact running in production was produced by their own build system and has not been swapped for something else. Which measure addresses that requirement?
選択肢
- Configure the cluster to pull the image again on every Pod start and the node always retrieves the current content from the registry.
- Store the image in a registry that requires credentials for every pull and only callers the platform trusts can retrieve the artifact.
- Scan the image for known vulnerabilities in the build pipeline and flawed layers are found early.
- Have the build system sign the artifact and verify that signature before the workload is admitted to the cluster.