DevOps

Container Supply Chain Security

SBOM (Syft, CycloneDX), image signing (Cosign, Sigstore), OCI standards, vulnerability scanning, registry security

22 питань зі співбесід·
Senior
1

What is an SBOM (Software Bill of Materials) in the context of container security?

Відповідь

An SBOM is a comprehensive inventory of all software components contained in a container image, including libraries, dependencies, and their versions. It enables rapid identification of known vulnerabilities and tracking of risky components in the supply chain. Automated SBOM generation with tools like Syft or CycloneDX has become essential practice for maintaining visibility into transitive dependencies and meeting compliance requirements.

2

What standard format is used by CycloneDX to represent an SBOM?

Відповідь

CycloneDX primarily uses JSON and XML formats to represent SBOMs, in accordance with the OWASP CycloneDX specification. These structured formats enable interoperability between different security tools and facilitate integration into CI/CD pipelines. JSON format is generally preferred for its lightweight nature and ease of parsing, while XML offers stricter schema validation for demanding enterprise environments.

3

What is Cosign in the Sigstore ecosystem?

Відповідь

Cosign is a container artifact signing and verification tool developed as part of the Sigstore project. It enables cryptographic signing of OCI images and verification of their authenticity without requiring complex PKI infrastructure. Cosign integrates easily into CI/CD workflows and supports keyless signatures via OIDC, significantly simplifying key management compared to traditional methods like GPG.

4

What is the main characteristic of the OCI (Open Container Initiative) standard for images?

5

What does Syft generate when analyzing a container image?

+19 питань зі співбесід

Інші теми співбесід DevOps

Version Control & Git

Junior
20 запитань

Linux Fundamentals

Junior
22 запитань

Shell Scripting & Bash

Mid-Level
20 запитань

Networking Basics

Junior
22 запитань

Docker Fundamentals

Junior
24 запитань

CI/CD Fundamentals

Junior
18 запитань

GitHub Actions

Mid-Level
22 запитань

GitLab CI/CD

Mid-Level
22 запитань

Jenkins

Mid-Level
22 запитань

Kubernetes Basics

Mid-Level
26 запитань

Kubernetes Networking

Mid-Level
24 запитань

Kubernetes Advanced

Mid-Level
24 запитань

Ingress & API Gateway

Mid-Level
20 запитань

Terraform Basics

Mid-Level
22 запитань

Terraform Advanced

Mid-Level
22 запитань

Ansible & Configuration Management

Mid-Level
20 запитань

AWS Essentials

Mid-Level
26 запитань

Azure Fundamentals

Mid-Level
22 запитань

GCP Fundamentals

Mid-Level
22 запитань

Monitoring & Prometheus

Mid-Level
22 запитань

Logging & ELK Stack

Mid-Level
20 запитань

Alerting & Incident Response

Mid-Level
20 запитань

Cloud Identity & Secrets

Mid-Level
22 запитань

CI/CD Pipeline Security

Mid-Level
20 запитань

Helm & Kubernetes

Mid-Level
20 запитань

Runtime & Cluster Security

Senior
24 запитань

Service Mesh & Istio

Senior
24 запитань

GitOps & ArgoCD

Senior
22 запитань

Progressive Delivery

Senior
20 запитань

Distributed Observability

Senior
22 запитань

Disaster Recovery & Backup

Senior
20 запитань

Performance Optimization

Senior
22 запитань

Cloud Cost Optimization

Senior
20 запитань

SRE Principles

Senior
24 запитань

Chaos Engineering

Senior
20 запитань

Platform Engineering

Senior
22 запитань

Опануй DevOps для наступної співбесіди

Отримай доступ до всіх питань, flashcards, технічних тестів, вправ code review та симуляторів співбесід.

Почни безкоштовно