Courseiva

200-901 Application Deployment and Security Practice Question

A team is reviewing its CI/CD pipeline for security weaknesses. The pipeline builds and deploys a containerized application. Which TWO practices best reduce the risk of a compromised build environment affecting the deployed application? (Choose two.)

⚠ Common exam trap

The trap here is assuming that reusing build agents and storing long-lived credentials is efficient, when both increase the persistence and blast radius of a compromise.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Run the build in an isolated, ephemeral environment that is destroyed after each pipeline run.

Isolated, ephemeral build environments and short-lived scoped credentials both limit the impact of a compromised build. The ephemeral environment prevents persistence, while short-lived credentials reduce the value of any stolen secrets. Persistent agents and long-lived credentials increase risk because a compromise can persist and be reused, and unsigned images remove verification of the deployed artifact.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Run the build in an isolated, ephemeral environment that is destroyed after each pipeline run.

    Why this is correct

    This is correct because an isolated, ephemeral build environment limits the persistence of any compromise. If an attacker compromises the build, the environment is destroyed after the run, so they cannot maintain access or tamper with future builds. It also prevents cross-contamination between pipeline runs and reduces the blast radius of a compromised build.

  • ✓

    Use short-lived, scoped credentials issued to the pipeline at runtime instead of persistent secrets.

    Why this is correct

    This is correct because short-lived, scoped credentials reduce the window and scope of abuse if the build environment is compromised. They are issued for the specific pipeline run and expire quickly, so an attacker cannot reuse them later. This limits the impact of a compromised build on the deployed application and other resources.

  • ✗

    Allow the build to push directly to the production registry without any image signing or verification.

    Why it's wrong here

    This is wrong because pushing unsigned images directly to production removes the ability to verify that the deployed artifact came from a trusted build. An attacker who compromises the build could push a malicious image. Image signing and verification are important controls that this practice omits.

  • ✗

    Store long-lived cloud credentials as environment variables in the CI/CD platform for all pipeline runs.

    Why it's wrong here

    This fails because long-lived credentials stored in the CI/CD platform are a high-value target and can be exfiltrated by a compromised build. They also remain valid indefinitely, so an attacker can use them long after the build. Best practice is to use short-lived, scoped credentials issued at runtime rather than persistent secrets.

  • ✗

    Reuse the same build agent for all pipelines to save time and avoid environment setup.

    Why it's wrong here

    This fails because reusing the same build agent allows state and potential compromises to persist across pipelines. An attacker who compromises the agent could affect subsequent builds or steal credentials from other pipelines. Ephemeral, isolated agents are preferred to prevent this persistence and cross-contamination.

About these practice questions

One of 975 original 200-901 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 200-901 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-901 exam.