200-901 Application Deployment and Security Practice Question
A developer maintains a Python library that is published to a package index and consumed by other teams. The build pipeline should ensure that a compromised maintainer account cannot publish a malicious version under the project's name. Which control should be configured on the pipeline?
⚠ Common exam trap
The trap here is assuming that stronger login controls prevent malicious publishing, when a stolen credential can still produce a validly uploaded artifact unless releases are cryptographically signed.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Sign release artifacts with a key held in the CI system's trusted identity and have consumers verify the signature.
Preventing a compromised account from publishing malicious code requires a control that does not depend solely on that account's credentials. Artifact signing with a key controlled by the trusted pipeline ties each release to a verifiable identity, and consumers who check the signature will reject anything not signed by that key. Account hardening, dependency pinning, and source analysis improve security elsewhere but cannot stop an authorized-but-malicious publish.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Pin dependency versions in requirements.txt so downstream installs are reproducible.
Why it's wrong here
Pinning versions improves reproducibility and limits surprise upgrades, but it governs what the project consumes, not who may publish the project itself. An attacker who can publish under the project name defeats pinning for anyone installing a new version. It does not address publisher authenticity.
- ✗
Enable two-factor authentication on the publishing account and use API tokens scoped to the project.
Why it's wrong here
Two-factor authentication and scoped tokens harden account access and limit token blast radius, which is valuable. However, they still rely on a credential that a compromised account or stolen token can use to publish. They raise the bar but do not cryptographically bind published artifacts to a trusted identity independent of the credential.
- ✓
Sign release artifacts with a key held in the CI system's trusted identity and have consumers verify the signature.
Why this is correct
Digital signatures bind the released artifact to a private key that only the trusted pipeline can use, so a stolen account credential alone cannot forge a valid release. Consumers who verify the signature reject artifacts not signed by the expected key. This provides the cryptographic guarantee that a compromised account cannot publish malicious code that passes verification.
- ✗
Run a linter and static analysis over the source before each publish step.
Why it's wrong here
Linting and static analysis catch code quality and some security defects in the source being published, but they do not authenticate the publisher. A malicious release that passes linting would still be accepted by consumers. These checks improve code hygiene without providing any guarantee about who produced the artifact.
Visual reference
Go deeper
Related to this question
About these practice questions
This 200-901 question is part of Courseiva's 975-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 200-901 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-901 exam.