Courseiva
mediumMultiple Choice

200-901 Practice Question: A security team wants to ensure that only signed…

A security team wants to ensure that only signed Docker images are deployed in production. Which CI/CD pipeline step validates the image signature before deployment?

⚠ Common exam trap

Candidates often confuse integrity verification (hash comparison) with authenticity verification (digital signatures), assuming a simple SHA check provides the same security as a full PKI-based signing scheme like Docker Content Trust.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Use Docker Content Trust with Notary to verify signatures.

Docker Content Trust (DCT) integrates with Notary to provide a framework for signing and verifying Docker images. When DCT is enabled in the CI/CD pipeline, the Docker client verifies the image's signature against a trusted signing key before allowing the image to be pulled or deployed, ensuring only images signed by authorized parties are used in production.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Use Docker Content Trust with Notary to verify signatures.

    Why this is correct

    Docker Content Trust enforces image signing through Notary, which validates the signature against the publisher's key before the image is pulled or run. This directly satisfies the stem's requirement that only signed images reach production, blocking unsigned or tampered images at the pipeline's verification step.

  • ✗

    Compare the image SHA with a known good hash.

    Why it's wrong here

    Comparing a SHA hash confirms the image bytes match a recorded digest, detecting tampering or corruption, but it does not verify a cryptographic signature or publisher identity. It is tempting because digest pinning is a genuine supply-chain control, and it would be the right step when the goal is immutability rather than signature validation.

  • ✗

    Run a vulnerability scan on the image.

    Why it's wrong here

    A vulnerability scan inspects packages and layers for known CVEs; it never checks whether the image carries a valid signature from a trusted signer. It is tempting because scanning is a standard CI/CD security gate, and it would be correct when the requirement is detecting vulnerable dependencies rather than enforcing signed images.

  • ✗

    Check the image size on registry.

    Why it's wrong here

    Image size is metadata about layer storage and has no cryptographic relationship to the image's contents or signer, so it cannot validate a signature. It is tempting because registry metadata is trivial to query, and it would be relevant when optimising pull bandwidth or storage, not when enforcing image provenance.

About these practice questions

This 200-901 question is part of Courseiva's 975-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 200-901 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-901 exam.