200-901 Application Deployment and Security Practice Question
A developer is designing a CI/CD pipeline that deploys to production. The team wants to ensure that a failed security scan blocks the deployment automatically. Which pipeline design element should be implemented?
⚠ Common exam trap
Watch out — candidates often confuse visibility with enforcement, assuming that generating scan reports is enough when the pipeline must actually fail to block deployment.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Make the security scan stage a required dependency of the deploy stage and fail the pipeline on non-zero exit
A security gate must be part of the pipeline flow and able to fail the build. Making the deploy stage depend on a successful scan, with the scanner exiting non-zero on violations, ensures vulnerable artifacts never reach production. Parallel or advisory scans cannot enforce this requirement.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Make the security scan stage a required dependency of the deploy stage and fail the pipeline on non-zero exit
Why this is correct
Configuring the deploy stage to depend on a successful security scan, and having the scan return a non-zero exit code on findings, causes the pipeline to halt before deployment. This enforces the gate automatically without manual intervention. It is the standard way to make quality checks mandatory in CI/CD.
- ✗
Schedule the security scan as a nightly job separate from the pipeline
Why it's wrong here
A nightly scan runs after deployments have already occurred and cannot block a specific build. Findings would be discovered too late to prevent a vulnerable release. Integration into the pipeline with a blocking gate is required for preventive control.
- ✗
Run the security scan in parallel with deployment to save time
Why it's wrong here
Running the scan in parallel means deployment can proceed before scan results are known, so a vulnerable build could reach production. This defeats the purpose of gating. The scan must complete successfully before deployment starts to provide any assurance.
- ✗
Configure the scan to only warn and continue on findings
Why it's wrong here
A warning-only configuration allows the pipeline to continue and deploy despite vulnerabilities. It provides visibility but no enforcement, so the requirement that a failed scan blocks deployment is not satisfied. The scan must be able to fail the build.
Go deeper
Related to this question
About these practice questions
One of 975 original 200-901 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 200-901 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-901 exam.