Which automated tool output is accepted by FedRAMP for vulnerability scanning of container-based infrastructure?
-
A
Only Nessus Professional scans
-
B
SCAP-validated or agency-approved container image scanners
-
C
Manual configuration reviews only
-
D
OWASP ZAP web scans exclusively