200-901 Application Deployment and Security Practice Question
A security engineer is configuring a CI/CD pipeline that builds container images. The pipeline must fail the build if the image contains a package with a known critical vulnerability. The scanner runs as a separate step after the image is built. Which approach correctly integrates vulnerability scanning into the pipeline?
⚠ Common exam trap
The trap here is believing that a scanner reporting findings is enough, when the pipeline only fails if the scanner returns a non-zero exit code.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Configure the scanner step to exit with a non-zero status when a critical vulnerability is detected, so the pipeline stage fails.
To enforce a security gate, the scanner must cause the pipeline to fail when it finds a critical vulnerability. A non-zero exit code from the scanner step is the standard mechanism CI/CD systems use to stop the pipeline. Notification-only or source-only approaches do not block deployment of the vulnerable image, so they do not satisfy the requirement.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Configure the scanner step to exit with a non-zero status when a critical vulnerability is detected, so the pipeline stage fails.
Why this is correct
This is correct because CI/CD systems treat a non-zero exit code from a step as a failure, which stops the pipeline and prevents the vulnerable image from being published. Setting the scanner's severity threshold to critical and letting it return a failing exit code enforces the gate automatically without manual review.
- ✗
Run the scanner with a flag that only prints findings to the log, then rely on the developer to review the log before merging.
Why it's wrong here
This fails because printing findings without failing the build does not enforce the security gate. A developer could merge despite critical findings, so the pipeline would not reliably prevent vulnerable images from progressing. The scenario requires the build to fail automatically, which this approach does not do.
- ✗
Add the scanner as a post-build notification that sends an email to the security team, then allow the pipeline to continue to deployment.
Why it's wrong here
This is wrong because a notification does not block the pipeline. The image would still be deployed even with a critical vulnerability, violating the requirement that the build must fail. Email alerts are useful for awareness but do not enforce a security gate.
- ✗
Run the scanner before the image is built, scanning only the source code repository for vulnerable dependencies.
Why it's wrong here
This fails because the requirement is to detect vulnerabilities in the built image, which may include base image packages and OS libraries not present in the source repository. Scanning only source dependencies would miss vulnerabilities introduced by the base image or installed system packages, so the gate would not cover the actual runtime artifact.
Go deeper
Related to this question
About these practice questions
One of 975 original 200-901 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 200-901 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-901 exam.