200-901 Application Deployment and Security Practice Question
A developer is reviewing a CI/CD pipeline that builds a Python application and pushes a Docker image to a registry. The pipeline currently runs as a single stage that installs dependencies, runs tests, and pushes the image. The team wants to ensure that the image is not pushed if any test fails. Which change should be made to the pipeline?
⚠ Common exam trap
The trap here is thinking that retrying tests or adding registry labels creates a quality gate, when the gate must be a conditional dependency between pipeline stages.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Split the pipeline into separate build, test, and push stages, and configure the push stage to run only if the test stage succeeds.
A quality gate is enforced by ordering pipeline stages and making the push conditional on test success. Splitting the pipeline into build, test, and push stages with a dependency between test and push ensures that a failed test stops the pipeline before the image is published. Retries, early pushes, or registry-side checks do not provide the same guarantee.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Add a retry loop around the test command so transient failures do not stop the pipeline.
Why it's wrong here
Retrying tests can mask real failures and does not prevent the image from being pushed when tests genuinely fail. The requirement is to block the push on test failure, not to make tests more tolerant. A retry loop also increases pipeline duration without adding a quality gate.
- ✗
Move the image push to the beginning of the pipeline so the registry is updated as early as possible.
Why it's wrong here
Pushing the image before tests run means a failing test cannot prevent the artifact from being published, which is the opposite of the requirement. It also risks distributing a broken image to consumers. The push must be gated on test success, not moved earlier.
- ✓
Split the pipeline into separate build, test, and push stages, and configure the push stage to run only if the test stage succeeds.
Why this is correct
Separating the stages and gating the push on test success ensures that a failing test halts the pipeline before the image is published. This prevents broken artifacts from reaching the registry and gives clear feedback about which stage failed. It is the standard way to enforce quality gates in CI/CD.
- ✗
Configure the registry to reject images that do not include a passing test report as a label.
Why it's wrong here
Registries generally do not inspect test reports or enforce pipeline logic; they store and distribute images. Relying on the registry to validate test results is not a reliable quality gate and may not be supported. The pipeline itself should prevent the push when tests fail.
Go deeper
Related to this question
About these practice questions
One of 975 original 200-901 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 200-901 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-901 exam.