Question 1
A financial services company is adopting cloud native practices and needs to ensure that all container images deployed to their production Kubernetes cluster are from a trusted, internal registry and have been scanned for critical vulnerabilities. Which combination of CNCF projects is best suited to enforce this policy at the time of deployment?
Answer and explanation
Correct answer: B
Harbor is a CNCF graduated project that provides a private container registry with integrated vulnerability scanning (like Trivy or Clair). Open Policy Agent (OPA) can be used as a Kubernetes admission controller to enforce policies, such as rejecting pods that attempt to use images from untrusted registries or images with known critical vulnerabilities. This combination directly addresses the requirements.