Problem Statement
What security risks can Docker images carry and how can you mitigate them?
Explanation
Docker images may include outdated dependencies, unpatched libraries, mis-configured permissions, or embedded secrets. Mitigation includes using minimal base images, scanning images for vulnerabilities, removing unnecessary tools in runtime images, applying least-privilege user, regularly updating images, and applying image signing or trusted registries. This awareness is required for production readiness.
Practice Sets
This question appears in the following practice sets:
