Courseiva

200-901 Application Deployment and Security Practice Question

A developer is designing a CI/CD pipeline that deploys to production. The team wants to ensure that a failed security scan blocks the deployment automatically. Which pipeline design element should be implemented?

⚠ Common exam trap

Watch out — candidates often confuse visibility with enforcement, assuming that generating scan reports is enough when the pipeline must actually fail to block deployment.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Make the security scan stage a required dependency of the deploy stage and fail the pipeline on non-zero exit

A security gate must be part of the pipeline flow and able to fail the build. Making the deploy stage depend on a successful scan, with the scanner exiting non-zero on violations, ensures vulnerable artifacts never reach production. Parallel or advisory scans cannot enforce this requirement.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Make the security scan stage a required dependency of the deploy stage and fail the pipeline on non-zero exit

    Why this is correct

    Configuring the deploy stage to depend on a successful security scan, and having the scan return a non-zero exit code on findings, causes the pipeline to halt before deployment. This enforces the gate automatically without manual intervention. It is the standard way to make quality checks mandatory in CI/CD.

  • ✗

    Schedule the security scan as a nightly job separate from the pipeline

    Why it's wrong here

    A nightly scan runs after deployments have already occurred and cannot block a specific build. Findings would be discovered too late to prevent a vulnerable release. Integration into the pipeline with a blocking gate is required for preventive control.

  • ✗

    Run the security scan in parallel with deployment to save time

    Why it's wrong here

    Running the scan in parallel means deployment can proceed before scan results are known, so a vulnerable build could reach production. This defeats the purpose of gating. The scan must complete successfully before deployment starts to provide any assurance.

  • ✗

    Configure the scan to only warn and continue on findings

    Why it's wrong here

    A warning-only configuration allows the pipeline to continue and deploy despite vulnerabilities. It provides visibility but no enforcement, so the requirement that a failed scan blocks deployment is not satisfied. The scan must be able to fail the build.

About these practice questions

One of 975 original 200-901 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 200-901 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-901 exam.