A security analyst is configuring a container scanning tool to identify vulnerabilities in Docker images before deployment. Which of the following tools is specifically designed for container image vulnerability scanning?
Trivy scans container images for known vulnerabilities in OS packages and application dependencies, integrating into CI pipelines before deployment. This satisfies the requirement for a tool specifically designed for container image vulnerability scanning, unlike general-purpose scanners.
Why this answer
Trivy is an open-source vulnerability scanner from Aqua Security specifically designed to scan container images, filesystems, and IaC for vulnerabilities and misconfigurations. It integrates directly with Docker and CI/CD pipelines to detect CVEs in OS packages and application dependencies before deployment. This makes it the correct tool for pre-deployment container image scanning.
Exam trap
CS0-004 often tests the confusion between network vulnerability scanners (Nessus, OpenVAS) and container-specific scanners (Trivy, Clair, Anchore) — candidates pick Nessus because it is the most familiar vulnerability tool.
How to eliminate wrong answers
Option A is wrong because Burp Suite is a web application security testing tool for HTTP traffic, not container image scanning. Option B is wrong because Nessus is a general-purpose network vulnerability scanner that targets hosts and services, not container image layers. Option D is wrong because OpenVAS is an open-source network vulnerability scanner similar to Nessus, also not designed for container image analysis.