A risk manager at a retail bank is assessing risks introduced by a new open-source container orchestration platform. The platform will host internal APIs that process non-public customer information. Which TWO of the following are the MOST significant risks that should be prioritized in the risk register? (Choose two.)
Hard-coded secrets in images or manifests are easily exposed through image layers, source repositories, or runtime environment variables. In a banking context, exposed API keys could allow attackers to bypass authentication and access customer data. This risk is both highly likely and high impact, and it can be mitigated through secret management tools, image scanning, and secure coding practices, warranting priority in the risk register.
Why this answer
Unpatched container images and hard-coded secrets directly threaten the confidentiality and integrity of non-public customer information. These risks are highly exploitable and can lead to data breaches, regulatory penalties, and reputational damage. Policy gaps, licensing costs, and community support delays are important but secondary; they do not represent immediate, high-impact threats to customer data in a banking context.
Exam trap
The trap here is focusing on governance or cost issues while overlooking that unpatched images and hard-coded secrets are the direct, high-impact threats to customer data.