A DevOps engineer is setting up a CI/CD pipeline to scan container images for vulnerabilities. They want to fail the pipeline if any critical vulnerabilities are found. Which command should they use to scan the image and produce a JSON output that can be parsed?
This is the correct command because it targets the container image (`trivy image`), restricts results to only critical-severity vulnerabilities with `--severity CRITICAL`, and outputs machine-readable JSON via `--output json`. The JSON format is ideally suited for CI/CD automation, allowing the pipeline to parse vulnerability data programmatically (e.g., with jq) and enforce policy based on exact vulnerability IDs. It directly matches the requirement to scan the built image and flag critical issues.
Why this answer
`trivy image` scans a container image. Use `--severity CRITICAL` to filter only critical vulnerabilities and `--format json` to produce machine-parseable JSON output. This lets the pipeline parse the JSON and fail on critical vulnerabilities.
Note: `--output` specifies an output file path, not the report format.
Exam trap
The trap is confusing `trivy fs` with `trivy image`, and confusing `--format` (which controls output format, such as JSON) with `--output` (which specifies a file path). The command must use `--format json`, not `--output json`.
How to eliminate wrong answers
Option A is wrong because `trivy fs` scans a filesystem or directory, not a container image, so it would not scan the image layers for vulnerabilities. Option C is wrong because `--format table` produces human-readable table output, not JSON, making it unsuitable for programmatic parsing in a pipeline. Option D is wrong because `--severity HIGH` filters for high-severity vulnerabilities, not critical, and it lacks `--output json` so the output is not in JSON format.