Courseiva
mediumMultiple Choice

200-901 Practice Question: During a CI/CD pipeline, a security scan reveals…

During a CI/CD pipeline, a security scan reveals that a Docker image contains a vulnerability in a base layer. Which action BEST addresses the issue?

⚠ Common exam trap

Cisco often tests the distinction between detection/monitoring (options C and D) and actual remediation (option B), trapping candidates who think run-time monitoring or ignoring the report is sufficient to address a build-time vulnerability.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Rebuild the image using an updated base image from a trusted registry.

The vulnerability exists in the base layer of the Docker image, which is immutable once built. The only way to eliminate the vulnerability is to rebuild the image using an updated base image from a trusted registry (e.g., Docker Hub official images or a private registry with patched images). This ensures the vulnerable packages are replaced with patched versions at the OS or application level, directly addressing the root cause.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Disable the security scanner to avoid false positives.

    Why it's wrong here

    Disabling the scanner removes the only mechanism that detects the vulnerable base layer, leaving the image built and shipped unchanged. It is tempting when teams distrust findings, but scanners are correctly disabled only for a specific rule after triage confirms a documented false positive, not for genuine base-image CVEs.

  • ✓

    Rebuild the image using an updated base image from a trusted registry.

    Why this is correct

    Rebuilding with an updated base image replaces the vulnerable layer at its source, since Docker layers are immutable and inherited from the parent image. Patching the running container or adding a scan stage leaves the flaw embedded, so this action directly satisfies the requirement to remediate the base-layer vulnerability before redeployment.

  • ✗

    Implement run-time security monitoring to detect exploitation.

    Why it's wrong here

    Run-time monitoring detects exploitation after deployment; it does not remove the vulnerable base layer from the image, so the CVE still ships. It is tempting because monitoring is a genuine defence-in-depth control, and would be the right choice when the requirement is detecting active attacks rather than remediating image contents.

  • ✗

    Add an exception to the vulnerability report.

    Why it's wrong here

    An exception records the vulnerability as accepted, leaving the vulnerable base layer in the image and unchanged in the registry. It is tempting because exceptions are legitimate for unreachable or accepted-risk findings, but they are the correct choice only when remediation is genuinely impossible or the risk is formally accepted.

About these practice questions

One of 975 original 200-901 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 200-901 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-901 exam.