200-901 Application Deployment and Security Practice Question
A team is reviewing its CI/CD pipeline for security weaknesses. The pipeline builds and deploys a containerized application. Which TWO practices best reduce the risk of a compromised build environment affecting the deployed application? (Choose two.)
⚠ Common exam trap
The trap here is assuming that reusing build agents and storing long-lived credentials is efficient, when both increase the persistence and blast radius of a compromise.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Run the build in an isolated, ephemeral environment that is destroyed after each pipeline run.
Isolated, ephemeral build environments and short-lived scoped credentials both limit the impact of a compromised build. The ephemeral environment prevents persistence, while short-lived credentials reduce the value of any stolen secrets. Persistent agents and long-lived credentials increase risk because a compromise can persist and be reused, and unsigned images remove verification of the deployed artifact.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Run the build in an isolated, ephemeral environment that is destroyed after each pipeline run.
Why this is correct
This is correct because an isolated, ephemeral build environment limits the persistence of any compromise. If an attacker compromises the build, the environment is destroyed after the run, so they cannot maintain access or tamper with future builds. It also prevents cross-contamination between pipeline runs and reduces the blast radius of a compromised build.
- ✓
Use short-lived, scoped credentials issued to the pipeline at runtime instead of persistent secrets.
Why this is correct
This is correct because short-lived, scoped credentials reduce the window and scope of abuse if the build environment is compromised. They are issued for the specific pipeline run and expire quickly, so an attacker cannot reuse them later. This limits the impact of a compromised build on the deployed application and other resources.
- ✗
Allow the build to push directly to the production registry without any image signing or verification.
Why it's wrong here
This is wrong because pushing unsigned images directly to production removes the ability to verify that the deployed artifact came from a trusted build. An attacker who compromises the build could push a malicious image. Image signing and verification are important controls that this practice omits.
- ✗
Store long-lived cloud credentials as environment variables in the CI/CD platform for all pipeline runs.
Why it's wrong here
This fails because long-lived credentials stored in the CI/CD platform are a high-value target and can be exfiltrated by a compromised build. They also remain valid indefinitely, so an attacker can use them long after the build. Best practice is to use short-lived, scoped credentials issued at runtime rather than persistent secrets.
- ✗
Reuse the same build agent for all pipelines to save time and avoid environment setup.
Why it's wrong here
This fails because reusing the same build agent allows state and potential compromises to persist across pipelines. An attacker who compromises the agent could affect subsequent builds or steal credentials from other pipelines. Ephemeral, isolated agents are preferred to prevent this persistence and cross-contamination.
Go deeper
Related to this question
About these practice questions
One of 975 original 200-901 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Cisco exam blueprint
This 200-901 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-901 exam.