SC-100 Design security solutions for infrastructure Practice Question
You are designing a secure DevOps pipeline for a critical application using GitHub Actions and Microsoft Defender for Cloud. You need to ensure that container images are scanned for vulnerabilities before being deployed to Azure Kubernetes Service (AKS). What should you implement?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Integrate Microsoft Defender for Containers with the CI/CD pipeline to scan images in Azure Container Registry.
The correct option is A: integrating Microsoft Defender for Containers with the CI/CD pipeline to scan images in Azure Container Registry. Defender for Containers provides image vulnerability scanning for ACR, and integrating it into the GitHub Actions pipeline lets you detect vulnerabilities before deployment to AKS, matching the requirement to scan images pre-deployment. Option B, GitHub Advanced Security, focuses on code and secret scanning rather than container image vulnerability assessment. Option C, Azure Policy, can audit or deny deployments based on vulnerability findings but does not itself perform image scanning in the pipeline. Option D, ACR Tasks, builds images but does not provide vulnerability scanning.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Integrate Microsoft Defender for Containers with the CI/CD pipeline to scan images in Azure Container Registry.
Why this is correct
Microsoft Defender for Containers natively provides vulnerability assessment for Azure Container Registry through its integration with CI/CD workflows. When an image is pushed to ACR, Defender automatically scans it using a continuously updated vulnerability database and exposes the findings in Microsoft Defender for Cloud. In a DevOps pipeline, you can query these scan results (e.g., using the Defender API or a pipeline step) to fail the release if high-severity vulnerabilities exceed a threshold, thus preventing vulnerable images from reaching AKS. This direct, artifact-level scanning makes it the correct choice for the security requirement.
- ✗
Enable GitHub Advanced Security for the repository.
Why it's wrong here
GitHub Advanced Security (GHAS) focuses on source-code-level risks in repositories—such as secret leaks and supply-chain dependencies—rather than on the final container image artifacts produced by a build. While GHAS can discover vulnerabilities in application code and open-source packages referenced in code, it does not inspect the OS packages or binaries inside a container image stored in Azure Container Registry. Therefore, enabling GHAS would not meet the requirement to scan the container image for vulnerabilities before deployment to AKS.
- ✗
Configure Azure Policy to require vulnerability assessment.
Why it's wrong here
Azure Policy is an organization-level compliance and governance service that can audit and enforce resource configurations, but it does not itself perform security scans of artifacts. A built-in policy like 'Vulnerabilities in Azure Container Registry images should be remediated' only checks whether the Defender for Containers vulnerability-assessment solution is properly enabled and reports on compliance status. Configuring Azure Policy would ensure the scanning environment is in place, but it cannot actively scan images or block a pipeline based on scan findings. Hence, this control is complementary, not a substitute for actual image vulnerability scanning.
- ✗
Use Azure Container Registry Tasks to build images.
Why it's wrong here
Azure Container Registry Tasks (ACR Tasks) is a workflow automation service that orchestrates building, patching, and testing container images at commit time within the registry, but it does not include a vulnerability scanner as a built-in capability. ACR Tasks can run your own scanning steps by invoking external tools, such as a curl command to the Defender API or an open-source scanner, but the Tasks feature itself only executes your defined task steps. Because the task definition would need to explicitly call a separate scanning service, using ACR Tasks alone does not satisfy the requirement for automated image vulnerability scanning.
Go deeper
Related to this question
About these practice questions
This SC-100 question is part of Courseiva's 605-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.