Courseiva
hardMultiple Select

200-901 Practice Question: A DevOps team is securing a CI/CD pipeline that…

A DevOps team is securing a CI/CD pipeline that deploys containerized applications to Kubernetes. Which THREE practices enhance security?

⚠ Common exam trap

Cisco often tests the misconception that 'containers are inherently isolated'—candidates may think privileges or root access are safe because containers are 'lightweight VMs,' but in reality, they share the host kernel, making privilege escalation a critical risk.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Implementing network policies to restrict pod communication.

Option A is correct because Kubernetes NetworkPolicies provide pod-level segmentation, restricting ingress and egress traffic so a compromised pod cannot freely reach other workloads, which enforces least-privilege communication in the cluster. Option C is correct because scanning container images for known CVEs before deployment shifts vulnerability detection into the CI stage, preventing flawed images from ever reaching the registry or cluster. Option E is correct because Kubernetes Secrets store sensitive data such as credentials and API keys separately from image and pod specs, allowing RBAC-controlled access and avoiding hardcoded plaintext values in manifests or environment files. Option B does not belong because privileged containers disable key isolation controls and grant near-host-level capabilities, greatly expanding the attack surface. Option D does not belong because running containers as root violates least privilege and means a container escape or exploit yields root-level access on the host.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Implementing network policies to restrict pod communication.

    Why this is correct

    Network policies act as pod-level firewalls, defining which pods may exchange traffic. Restricting pod communication limits lateral movement if a container is compromised, directly satisfying the pipeline's requirement to harden the Kubernetes cluster's runtime network segmentation.

  • ✗

    Allowing containers to run with privileges.

    Why it's wrong here

    Privileged containers bypass namespace isolation and can access host devices and kernel capabilities, directly undermining pipeline security. It is tempting because some workloads need host access, but that scenario requires privileged mode only for specific system-level agents, not general application containers.

  • ✓

    Scanning container images for vulnerabilities before deployment.

    Why this is correct

    Image scanning inspects layers against known CVE databases before the image reaches the registry or cluster. Catching vulnerable base images and dependencies at build time prevents deploying exploitable artefacts, satisfying the pipeline's need to block flawed images pre-deployment.

  • ✗

    Running containers as root.

    Why it's wrong here

    Running as root grants full in-container privileges, so a compromised process can escalate and modify the filesystem freely. It is tempting because default images often run as root, but least-privilege hardening requires a non-root user via securityContext.

  • ✓

    Using Kubernetes Secrets for sensitive environment variables.

    Why this is correct

    Kubernetes Secrets store credentials as base64-encoded objects mounted at runtime rather than baked into images or manifests. This keeps sensitive environment variables out of source control and image layers, satisfying the pipeline's requirement to protect deployment credentials.

Quick reference

Access Control Model Comparison

ModelAcronymWho Controls Access?Best For
Discretionary Access ControlDACResource ownerSmall teams, file shares
Mandatory Access ControlMACSystem / security labelsClassified govt / military
Role-Based Access ControlRBACAdministrator (via roles)Enterprise environments
Attribute-Based Access ControlABACPolicy engine (user + resource attributes)Fine-grained, dynamic policies
Rule-Based Access ControlRuBACSystem rules / ACLsFirewall rules, network ACLs

About these practice questions

This 200-901 question is part of Courseiva's 975-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 200-901 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-901 exam.