200-901 · domain
Application Deployment and Security
This domain covers deploying applications securely on Cisco platforms and in CI/CD pipelines. It tests Docker image builds and container troubleshooting, Kubernetes persistent volumes, secret management, and Cisco-specific deployment tooling like Intersight and AppDynamics. Expect scenario questions where you pick the correct command, volume type, or secret-handling practice rather than recite definitions.
Focused practice
Practice Application Deployment and Security questions
Scored sessions drawing only from this domain — pick a length below.
Start 20-question practice test →What this domain covers
What to know about Application Deployment and Security
Be able to build and debug a Docker image, choose the right Kubernetes volume for persistent data, and manage secrets safely in a pipeline. The single most important thing is diagnosing why a container or pod failed using the correct command before changing configuration.
Dockerfile instructions and docker run, build, logs, and inspect commands for container troubleshooting
Kubernetes persistent volume types such as PersistentVolume and PersistentVolumeClaim for stateful pods
Managing secrets in CI/CD using vaults, environment injection, and avoiding hardcoded credentials
Cisco Intersight, AppDynamics, and CI/CD pipeline integration for application deployment and monitoring
Watch out for
Common Application Deployment and Security exam traps
- ▸Using docker logs when the container never started, instead of docker inspect or checking exit codes and events
- ▸Storing secrets in Dockerfiles, image layers, or committed .env files instead of a secrets manager or CI variable store
- ▸Assuming emptyDir or hostPath persists data after a pod is deleted, when only a PersistentVolume does
Question index
All Application Deployment and Security questions (123)
Click any question to see the full explanation, or start a practice session above.
Which TWO practices help prevent hardcoded credentials in application code? (Choose TWO.)
Medium2A platform team is hardening a containerized application before production. They want to reduce the attack surface of the running containers themselves. Which two practices directly reduce the privileges available to a compromised container process? (Choose two.)
Medium3A developer is writing a REST API client in Python that authenticates to a controller using HTTP Basic authentication over the network. The developer wants to ensure credentials are never exposed on the wire in readable form. Which implementation detail is required?
Hard4A developer is writing a Python application that calls a REST API. The API requires an OAuth 2.0 bearer token. The token must not be stored in the source code. Which approach should the developer use to make the token available to the application at runtime?
Easy5A developer is building a Python microservice that will run in a Docker container on a shared host. The application must read its database connection string and API token from environment variables at runtime, and the developer wants to avoid baking those secrets into the image. Which approach best satisfies this requirement?
Medium6A Kubernetes pod has two containers: a main application and a sidecar proxy. They need to communicate via localhost. Which pod networking model allows this?
Hard7A developer needs to share a Docker image with a colleague. They decide to push the image to a registry. Which Docker command pushes an image to a registry?
Easy8Which Docker network driver allows a container to share the host's network stack, giving it direct access to host interfaces?
Easy9Which THREE steps are essential in a typical CI/CD pipeline for a containerized application? (Choose THREE.)
Hard10A team is reviewing its CI/CD pipeline for security weaknesses. The pipeline builds and deploys a containerized application. Which TWO practices best reduce the risk of a compromised build environment affecting the deployed application? (Choose two.)
Hard11A developer is using the Cisco Meraki Dashboard API to retrieve the list of organizations associated with an API key. The script must handle the response and avoid exposing the API key. Which HTTP header should be used to supply the API key?
Medium12A developer is deploying an application to a Kubernetes cluster and must ensure that the application's configuration values, such as a database hostname and port, are injected as environment variables without storing them in the container image. Which Kubernetes resource should be used?
Hard13A developer is writing a Python script that must call a Cisco DNA Center REST API. The script must authenticate with a username and password over HTTPS and receive a token that is valid for subsequent API calls. The developer wants to avoid embedding the credentials in the script. Which approach should be used?
Medium14A development team is adopting container security practices for their Docker-based microservices. They want to reduce the attack surface of their running containers. Which TWO practices should they implement? (Choose two.)
Medium15A Docker container running a web application needs to be accessible on the host's port 8080. The application inside the container listens on port 80. Which docker run command achieves this?
Medium16A developer wants to run a Docker container in detached mode, mapping host port 8080 to container port 80, and mounting a host directory for persistent data. Which command accomplishes this?
Medium17A developer is preparing a Python application for deployment to a Kubernetes cluster. The application reads configuration values such as the database host and API endpoint from a file mounted at /etc/config/app.conf. The values differ between the staging and production clusters. Which Kubernetes resource should the developer use to inject these values into the pod without baking them into the container image?
Medium18In a Kubernetes deployment, a developer needs to expose a set of pods internally within the cluster on a stable IP address. The pods are stateless and serve HTTP traffic. Which Service type should be used?
Medium19A developer is building a container image for a Node.js API. The Dockerfile currently starts with FROM node:18, copies source code, and runs npm install. Builds are slow because dependencies are reinstalled on every code change. The developer wants to leverage Docker layer caching so that npm install runs only when package.json changes. Which change should be made to the Dockerfile?
Medium20A company deploys a microservice using Kubernetes. The service must be accessible externally via a stable IP address and load-balanced across pods. Which Service type should be used?
Medium21A Kubernetes deployment is configured with replicas: 3. During a rolling update, the deployment strategy is set to RollingUpdate with maxSurge: 1 and maxUnavailable: 0. What is the maximum number of pods that will be running during the update?
Hard22A developer is deploying a containerized application to a Kubernetes cluster. The application must be accessible from outside the cluster on a stable IP address that does not change if the underlying pods are rescheduled. Which Kubernetes Service type should be used?
Medium23A DevOps engineer is deploying a containerized application to a Kubernetes cluster. The application needs to read a database password at runtime, and the team wants the value to be injected as an environment variable without storing it in the container image or the Deployment manifest. Which Kubernetes resource should be used?
Medium24A DevNet engineer is building a Python script that calls the Cisco Webex Teams API to post a message. The script currently stores the access token in a plain text variable at the top of the file, which is committed to a Git repository. The team wants to keep the token out of source control while still allowing the script to authenticate. Which approach should be used?
Medium25A developer is writing a Python script that calls a REST API. The script currently contains the API key as a string literal. The team wants to move the key out of source control and inject it at runtime in a CI/CD pipeline. Which approach best meets this requirement?
Easy26A security team is reviewing a CI/CD pipeline that builds container images and pushes them to a registry. They want to reduce the attack surface of the resulting images and ensure that only trusted images are deployed. Which TWO practices should be implemented? (Choose two.)
Hard27A CI/CD pipeline for a Python project should run unit tests and check for known vulnerabilities in dependencies. Which tool can be integrated into the pipeline to perform dependency scanning?
Medium28A developer is building a CI/CD pipeline that must securely manage secrets such as API keys and database passwords. Which two practices should be implemented to protect these secrets throughout the pipeline? (Choose two.)
Medium29A developer is writing a unit test for a Python function that calls the Cisco Meraki Dashboard API to retrieve a list of organizations. The test must run without making real HTTP requests to the Meraki cloud. Which technique should be used to isolate the function under test?
Easy30A development team runs a Python Flask API in a Docker container. The image was built with the Flask development server bound to 0.0.0.0:5000, and the container is started with the published port mapping 8080:5000. Users report that requests to the host on port 5000 are refused, while port 8080 works. Which statement explains this behaviour?
Hard31In a Kubernetes cluster, you need to expose a set of pods running a web application to external traffic on a specific port. Which Service type should you use to provide a stable external IP address?
Hard32A Kubernetes administrator wants to use kubectl to troubleshoot a pod named 'my-pod' that is not starting. Which TWO commands are useful? (Choose two.)
Hard33A Kubernetes pod runs two containers that need to share a filesystem. Which volume type should be used to enable file sharing between the containers within the same pod?
Medium34A developer is writing a web application and needs to prevent SQL injection attacks. Which coding practice is most effective?
Medium35A developer is writing a Python script that interacts with a REST API. The API requires authentication using a token. Which HTTP header should the developer include in the request to pass the token?
Easy36A developer is building a container image for a Python application using Docker. The Dockerfile contains several instructions, including a RUN pip install command that downloads dependencies. The developer wants to reduce the final image size and improve build cache efficiency. Which Dockerfile instruction should be used to combine multiple commands and avoid leaving unnecessary files in the image layer?
Medium37A security review of a CI/CD pipeline finds that build jobs run with credentials that have far more privilege than needed, and that the same long-lived token is reused across repositories. Which TWO changes reduce the blast radius if a pipeline credential is compromised? (Choose two.)
Medium38A CI/CD pipeline is configured to build a Docker image, run unit tests, and push the image to a registry. To ensure that only successfully tested images are pushed, which stage order is correct?
Hard39A web application is vulnerable to SQL injection. Which secure coding practice should the developer implement in the code to prevent this?
Medium40An engineer is troubleshooting an application running in a Docker container. The container is running but the application is not responding. The Dockerfile EXPOSE instruction lists port 8080, and the container was started with the command: docker run -d -p 8080:80 myapp. Which command should the engineer use to verify the application's actual listening port inside the container?
Medium41A development team is using Docker Compose to run a multi-container application. They need to ensure that the web service can resolve the hostname 'db' to the database container's IP address. Which network configuration in the docker-compose.yml file achieves this?
Hard42Which Docker networking mode provides the most isolation by not connecting the container to any network?
Easy43A developer is writing a Python script that calls a REST API protected by OAuth 2.0. The script runs unattended on a server and must obtain an access token without any user interaction. The authorization server supports the client credentials grant. Which flow should the developer implement?
Easy44A developer has a Docker container running a database. They need to inspect the database logs to debug a connection issue. Which command will show the logs in real-time?
Hard45A developer pushes a container image to Docker Hub and then discovers that the image layers contain an .env file with production API keys. The team wants future builds to fail automatically in the CI pipeline when secrets are detected in the image before any push occurs. Which approach best addresses this requirement?
Medium46A developer is creating a Dockerfile for a Python Flask application. The application runs on port 5000. Which directive should be used to document that the container listens on this port?
Easy47A Docker container needs to be started in detached mode with port mapping from host port 8080 to container port 80. Which command accomplishes this?
Easy48Which THREE options are valid methods to expose a Kubernetes service to external traffic?
Hard49A developer is writing a Dockerfile for a Node.js application. Which TWO instructions are commonly used to define the command that runs when the container starts?
Medium50A Kubernetes Service must expose a pod running a database to other pods in the same cluster, but not externally. Which Service type should be used?
Hard51A developer runs the command: docker run -d -p 8080:80 --name web nginx. Which of the following best describes what happens?
Easy52A CI/CD pipeline for a microservice application includes stages: code commit, build Docker image, push to registry, deploy to staging, run integration tests, and deploy to production. The team wants to ensure that if integration tests fail, the pipeline stops and does not proceed to production. Which CI/CD concept is used to enforce this behavior?
Medium53A Kubernetes pod needs to read configuration data such as database hostname, which is non-sensitive and may change across environments. Which resource should be used to store this data and inject it into the pod?
Medium54In a Docker Compose file, you want to ensure that the 'web' service starts only after the 'db' service is healthy. Which key should you use under the 'web' service?
Medium55Which TWO commands are used to view information about Docker containers? (Select two.)
Medium56In a docker-compose.yaml file, which key is used to define the container image to be built from a Dockerfile in the current directory?
Easy57A developer is designing a CI/CD pipeline that deploys to production. The team wants to ensure that a failed security scan blocks the deployment automatically. Which pipeline design element should be implemented?
Hard58A developer maintains a Python library that is published to a package index and consumed by other teams. The build pipeline should ensure that a compromised maintainer account cannot publish a malicious version under the project's name. Which control should be configured on the pipeline?
Hard59A developer writes a web application that accepts user input and displays it on a page. To prevent cross-site scripting (XSS), what is the most effective defense?
Medium60A developer needs to retrieve a secret stored in HashiCorp Vault from a CI job. The Vault administrator has enabled the AppRole auth method. Which sequence correctly authenticates and reads the secret using the Vault HTTP API?
Easy61A developer needs to enforce HTTPS for a web application. Which security measure should be implemented in the application or reverse proxy?
Easy62A CI/CD pipeline includes stages for security scanning. Which TWO tools or services are specifically designed for dependency vulnerability scanning?
Medium63A security team is reviewing a Python application that integrates with Cisco DNA Center. The application authenticates with a username and password and stores them in a configuration file that is deployed to multiple servers. The team wants to reduce the risk of credential exposure while keeping the application functional. Which TWO actions should be taken? (Choose two.)
Hard64A Kubernetes environment has multiple teams sharing the same cluster. One team wants to deploy applications without interfering with other teams' resources. Which Kubernetes resource should be used to isolate the team's resources?
Medium65A security team requires that a web application's API calls to an internal service use mutual TLS. The application runs in a Kubernetes pod and the team wants the certificate and private key mounted as files without embedding them in the container image. Which Kubernetes resource should be used to provide the certificate and key to the pod?
Hard66A developer is reviewing a CI/CD pipeline that builds and deploys a containerized application. The team wants to protect sensitive values such as API keys and registry passwords used during the pipeline. Which TWO practices should be used? (Choose two.)
Medium67A Kubernetes pod needs to run a database that requires persistent storage. Which volume type should be used to store data that persists beyond the pod lifecycle?
Hard68A company is deploying a containerized application to a Kubernetes cluster. The security team requires that the container runs as a non-root user and that the root filesystem is read-only. Which Kubernetes security context settings should be applied to the pod specification to meet these requirements?
Hard69A developer is building a container image for an application and wants to minimize the attack surface by ensuring the container does not run as root. The image is based on a Linux distribution. Which Dockerfile instruction should be used to specify a non-root user for the container process?
Easy70A developer needs to store a database password securely in a Kubernetes cluster. Which resource should be used?
Medium71A Kubernetes pod contains two containers that need to share a local filesystem. Which volume type should be used to enable this?
Medium72A CI/CD pipeline uses GitLab CI. The pipeline must build a Docker image and then run security scans on the image before pushing. Which GitLab CI keyword allows defining a sequence of jobs that must run in order?
Medium73A developer creates a Dockerfile for a Python web application. Which instruction should be used to copy the application source code into the container image?
Easy74In a Docker Compose file, a service 'web' depends on 'db'. The 'db' service uses a volume to persist data. Which compose key ensures that the database starts before the web service?
Medium75A developer needs to view the logs of a running Docker container with ID 'abc123'. Which command should be used?
Medium76A security review of a containerized application finds that the running process has far more privileges than it needs. Which TWO changes reduce the attack surface of the container at runtime? (Choose two.)
Medium77A developer needs to ensure that environment variables containing database credentials are not hardcoded in the application code. Which approach is most secure for managing secrets in a CI/CD pipeline?
Medium78A team is hardening a Kubernetes deployment that exposes a web API. They want to reduce the impact of a container compromise and enforce network segmentation. Which TWO configurations should they apply? (Choose two.)
Medium79An application running on a Cisco IOS XE device must call an external REST API that uses a self-signed certificate. The developer's Python script using the requests library fails with an SSL verification error. The security team requires that the script still validates the server identity. Which approach satisfies the requirement?
Hard80A CI/CD pipeline using GitHub Actions needs to build a Docker image and push it to Docker Hub. Which event trigger should be used to run the workflow only when code is pushed to the main branch?
Hard81A developer wants to ensure that a containerized application restarts automatically if it exits with a non-zero code. The application is run using Docker. Which flag should be used?
Hard82A Kubernetes Deployment is configured with rolling update strategy. A new version of the image is pushed, and the deployment is updated. During the rollout, the new pods are failing health checks. Which command can be used to pause the rollout and prevent further updates?
Hard83A development team is implementing security controls for a containerized application deployed on Kubernetes. They need to ensure that containers run with least privilege and that sensitive information is protected. Which TWO measures should be implemented? (Choose two.)
Medium84A development team is building a container image for a Node.js API. The Dockerfile currently uses the instruction `COPY . /app` before `RUN npm install`. A security review flags that the image contains local `.env` files and `.git` history. Which approach best prevents these files from entering the build context while keeping the Dockerfile functional?
Medium85A developer is writing a Dockerfile for a Node.js application. They want to set a build-time variable for the application version that can be changed without modifying the Dockerfile. Which instruction should be used?
Medium86A team uses a Jenkins declarative pipeline to deploy a microservice. The pipeline includes stages: Checkout, Build Docker Image, Run Unit Tests, Push to Registry, Deploy to Staging, and Deploy to Production. Which stage should run immediately after 'Build Docker Image' to ensure code quality before the image is pushed?
Medium87A DevOps engineer is deploying a containerized application to a Kubernetes cluster. The application requires a configuration file that contains non-sensitive settings, such as the application's log level and API endpoint. The engineer wants to manage this configuration separately from the container image and make it easily updatable without rebuilding the image. Which Kubernetes resource should be used?
Medium88Which TWO actions are best practices for managing secrets in a CI/CD pipeline?
Medium89A developer is using Docker Compose to run a multi-service application. Which THREE keys are valid top-level keys in a docker-compose.yml file? (Choose three.)
Medium90A developer needs to apply a Kubernetes deployment manifest from a file named 'deployment.yaml'. Which kubectl command should be used?
Medium91A developer commits code to a GitHub repository and wants automated tests to run, followed by building a Docker image and pushing it to Docker Hub only if tests pass. Which CI/CD tool can be configured using a YAML file placed in the .github/workflows directory?
Medium92A developer is writing a Python script that retrieves a device list from a Cisco DNA Center controller. The script must read the controller address and an API token from the environment rather than embedding them in source code. Which practice best supports secure, repeatable execution across developer machines and CI runners?
Easy93A developer needs to prevent SQL injection in a web application. Which coding practice should be used when constructing database queries?
Medium94A CI/CD pipeline includes stages for code commit, build, unit test, integration test, staging deploy, and production deploy. Which change would best prevent a faulty build from reaching production?
Medium95A developer needs a repeatable, isolated environment that contains Python 3.11, a specific set of pip packages, and the team's application code, so that every engineer and the CI runner execute identical builds. Which artifact should the developer create to meet this requirement?
Easy96A developer wants to perform a rolling update of a Kubernetes Deployment. Which command will update the image and initiate the rollout?
Medium97A DevOps engineer runs a container using 'docker run -d -p 8080:80 nginx'. The host firewall blocks incoming traffic on port 8080 from external networks but allows from the local host. Which command would allow the engineer to test the container's web server from the same machine?
Medium98Which THREE are valid Kubernetes Service types? (Select three.)
Hard99A developer runs 'docker run -d -p 8080:80 --name web nginx:alpine'. The container fails to start. Which command is the most appropriate to investigate the issue?
Medium100In Docker, which command is used to build an image from a Dockerfile and tag it as 'myapp:v1'?
Easy101An application deployed on a Kubernetes cluster must call an external payment API. The security team requires that the API credential never be stored in the container image, never appear in the pod specification, and be rotatable without rebuilding or redeploying the application. Which approach meets all three requirements?
Hard102Which Docker command is used to view the logs of a running container in real-time?
Medium103A developer is writing a web application and wants to prevent SQL injection attacks. Which coding practice should be followed when constructing SQL queries?
Medium104Which TWO Kubernetes resources are used to provide configuration data to pods? (Choose TWO.)
Medium105A developer creates a Dockerfile with the following content: FROM python:3.9-slim, COPY app.py /app/, RUN pip install flask, EXPOSE 5000, CMD ["python", "/app/app.py"]. When building the image with 'docker build -t myapp .', what is the purpose of the EXPOSE instruction?
Easy106A developer wants to create a Docker image that runs a Python application. Which instruction should be placed at the end of the Dockerfile to specify the command that runs when the container starts?
Easy107In a CI/CD pipeline using Jenkins, which stage is typically executed immediately after the build stage to ensure code quality before deployment?
Medium108A security engineer is configuring a CI/CD pipeline that builds container images. The pipeline must fail the build if the image contains a package with a known critical vulnerability. The scanner runs as a separate step after the image is built. Which approach correctly integrates vulnerability scanning into the pipeline?
Hard109A developer is writing a Python application that interacts with a REST API. The API requires authentication using an API key. The developer wants to avoid hardcoding the API key in the source code. Which approach should be used to securely provide the API key to the application?
Medium110A team uses GitHub Actions for CI/CD. Their workflow includes a job that builds a Docker image and pushes it to a private registry. The job needs to authenticate to the registry using secrets stored in GitHub. Which approach is most secure for passing credentials?
Hard111A developer runs 'docker-compose up -d' for a multi-service application. What does the '-d' flag do?
Easy112In a Docker Compose file, which key is used to define the dependency order between services?
Easy113A developer is reviewing a CI/CD pipeline that builds a Python application and pushes a Docker image to a registry. The pipeline currently runs as a single stage that installs dependencies, runs tests, and pushes the image. The team wants to ensure that the image is not pushed if any test fails. Which change should be made to the pipeline?
Hard114A developer is implementing secure coding practices to prevent SQL injection. Which approach is most effective when building a SQL query with user input?
Hard115A developer is building a microservice that must call an internal API. The API uses mutual TLS (mTLS), and the service must validate the server certificate against a private CA. Which configuration should the client use to verify the server identity?
Hard116A team deploys a containerized web application and wants to verify that the image running in production was built from the reviewed source and has not been altered since. Which practice directly provides this guarantee?
Easy117A developer is deploying a web application to a Kubernetes cluster. The application must be reachable from the internet on port 443, and the team wants the cluster to automatically provision a TLS certificate. Which Kubernetes resource should the developer create to expose the application with TLS termination and automatic certificate management?
Medium118In a Docker bridge network, two containers can communicate with each other using which identifier by default?
Medium119A company is adopting DevSecOps practices. Which THREE practices should be implemented to secure application deployment?
Hard120A developer is configuring a GitHub Actions workflow that must authenticate to AWS to push an image to Amazon ECR. The security team prohibits long-lived AWS access keys in repository secrets. Which authentication method should the workflow use?
Hard121A developer is using Docker Compose to define a multi-container application. The application requires a database container and a web server container that must communicate with each other. Which Docker Compose file section defines the individual containers and their configurations?
Easy122A developer has built a container image locally and needs to push it to Docker Hub so a CI runner can pull it. The image is currently tagged only as `webapp:latest`. The Docker Hub repository is `devopsuser/webapp`. Which command sequence correctly prepares and uploads the image?
Medium123A development team is using Cisco Intersight to manage their on-premises and cloud infrastructure. They want to ensure that API access to Intersight is secure and follows best practices. Which TWO measures should they implement to protect their Intersight API credentials and access? (Choose two.)
HardOther domains
All 200-901 exam domains
Frequently asked questions
- What does the Application Deployment and Security domain cover on the 200-901 exam?
- Be able to build and debug a Docker image, choose the right Kubernetes volume for persistent data, and manage secrets safely in a pipeline. The single most important thing is diagnosing why a container or pod failed using the correct command before changing configuration.
- How many questions are in this domain?
- This page lists all 123 Application Deployment and Security questions in the 200-901 question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
- What is the best way to practise this domain?
- Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
- Can I practise only Application Deployment and Security questions?
- Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.