hardMultiple Select
200-901 Practice Question: A DevOps team is securing a CI/CD pipeline that…
A DevOps team is securing a CI/CD pipeline that deploys containerized applications to Kubernetes. Which THREE practices enhance security?
⚠ Common exam trap
Cisco often tests the misconception that 'containers are inherently isolated'—candidates may think privileges or root access are safe because containers are 'lightweight VMs,' but in reality, they share the host kernel, making privilege escalation a critical risk.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Implementing network policies to restrict pod communication.
Option A is correct because Kubernetes NetworkPolicies provide pod-level segmentation, restricting ingress and egress traffic so a compromised pod cannot freely reach other workloads, which enforces least-privilege communication in the cluster. Option C is correct because scanning container images for known CVEs before deployment shifts vulnerability detection into the CI stage, preventing flawed images from ever reaching the registry or cluster. Option E is correct because Kubernetes Secrets store sensitive data such as credentials and API keys separately from image and pod specs, allowing RBAC-controlled access and avoiding hardcoded plaintext values in manifests or environment files. Option B does not belong because privileged containers disable key isolation controls and grant near-host-level capabilities, greatly expanding the attack surface. Option D does not belong because running containers as root violates least privilege and means a container escape or exploit yields root-level access on the host.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Implementing network policies to restrict pod communication.
Why this is correct
Network policies act as pod-level firewalls, defining which pods may exchange traffic. Restricting pod communication limits lateral movement if a container is compromised, directly satisfying the pipeline's requirement to harden the Kubernetes cluster's runtime network segmentation.
- ✗
Allowing containers to run with privileges.
Why it's wrong here
Privileged containers bypass namespace isolation and can access host devices and kernel capabilities, directly undermining pipeline security. It is tempting because some workloads need host access, but that scenario requires privileged mode only for specific system-level agents, not general application containers.
- ✓
Scanning container images for vulnerabilities before deployment.
Why this is correct
Image scanning inspects layers against known CVE databases before the image reaches the registry or cluster. Catching vulnerable base images and dependencies at build time prevents deploying exploitable artefacts, satisfying the pipeline's need to block flawed images pre-deployment.
- ✗
Running containers as root.
Why it's wrong here
Running as root grants full in-container privileges, so a compromised process can escalate and modify the filesystem freely. It is tempting because default images often run as root, but least-privilege hardening requires a non-root user via securityContext.
- ✓
Using Kubernetes Secrets for sensitive environment variables.
Why this is correct
Kubernetes Secrets store credentials as base64-encoded objects mounted at runtime rather than baked into images or manifests. This keeps sensitive environment variables out of source control and image layers, satisfying the pipeline's requirement to protect deployment credentials.
Quick reference
Access Control Model Comparison
| Model | Acronym | Who Controls Access? | Best For |
|---|---|---|---|
| Discretionary Access Control | DAC | Resource owner | Small teams, file shares |
| Mandatory Access Control | MAC | System / security labels | Classified govt / military |
| Role-Based Access Control | RBAC | Administrator (via roles) | Enterprise environments |
| Attribute-Based Access Control | ABAC | Policy engine (user + resource attributes) | Fine-grained, dynamic policies |
| Rule-Based Access Control | RuBAC | System rules / ACLs | Firewall rules, network ACLs |
Go deeper
Related to this question
About these practice questions
This 200-901 question is part of Courseiva's 975-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 200-901 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-901 exam.