問題文
A team relies on scanning images in the registry and argues that a cluster-side connector is therefore unnecessary. Which requirement does that position fail?
選択肢
- Detection of vulnerabilities in operating system packages inside the image, since package-level analysis is performed by the cluster-side connector and the registry scanner reports only the presence of secrets and malicious files.
- Anything about the running cluster's own objects and settings, and any ability to refuse a workload at the point it is admitted.
- The ability to associate images with their base images, so a weakness inherited from a shared base cannot be traced back to the base that introduced it.
- Detection of secrets inside the image, since a registry scan reads the package list and stops there without looking at the files themselves.