Courseiva

200-901 · topic practice

Application Deployment and Security practice questions

This domain covers deploying applications securely on Cisco platforms and in CI/CD pipelines. It tests Docker image builds and container troubleshooting, Kubernetes persistent volumes, secret management, and Cisco-specific deployment tooling like Intersight and AppDynamics. Expect scenario questions where you pick the correct command, volume type, or secret-handling practice rather than recite definitions.

Courseiva uses original exam-style practice questions designed for learning and revision. The goal is to understand the concepts, recognise exam patterns, and improve through explanations — not memorise copied exam dumps.

Editorial oversight:Johnson Ajibi· MSc IT Security, IEEE Senior Member
20 questionsDomain: Application Deployment and Security

What the exam tests

What to know about Application Deployment and Security

Be able to build and debug a Docker image, choose the right Kubernetes volume for persistent data, and manage secrets safely in a pipeline. The single most important thing is diagnosing why a container or pod failed using the correct command before changing configuration.

Dockerfile instructions and docker run, build, logs, and inspect commands for container troubleshooting

Kubernetes persistent volume types such as PersistentVolume and PersistentVolumeClaim for stateful pods

Managing secrets in CI/CD using vaults, environment injection, and avoiding hardcoded credentials

Cisco Intersight, AppDynamics, and CI/CD pipeline integration for application deployment and monitoring

Watch out for

Common Application Deployment and Security exam traps

  • ▸Using docker logs when the container never started, instead of docker inspect or checking exit codes and events
  • ▸Storing secrets in Dockerfiles, image layers, or committed .env files instead of a secrets manager or CI variable store
  • ▸Assuming emptyDir or hostPath persists data after a pod is deleted, when only a PersistentVolume does

Practice set

Application Deployment and Security questions

20 questions · select your answer, then reveal the explanation

Question 1mediummultiple choice
Study the full Python automation breakdown →

A CI/CD pipeline has a stage that runs security vulnerability scans on dependencies. Which tool is specifically designed to scan Python packages for known vulnerabilities?

In a Docker Compose file with multiple services, one service depends on another to be healthy before starting. Which key should be used to express this dependency and ensure the dependent service is started first?

Which TWO Docker network drivers allow a container to communicate with the host's network stack directly?

A Kubernetes Deployment has replicas: 3. The team updates the container image to a new version. The rollout gets stuck because the new pod fails readiness probes. Which kubectl command will display the rollout status and help diagnose the issue?

A developer is deploying a containerized application with Docker Compose. The application requires environment variables for database credentials that should not be hardcoded in the docker-compose.yml file. Which two methods securely provide these credentials? (Choose two.)

A Kubernetes cluster has a deployment named 'frontend' that needs to be updated to a new image version. The update should be performed with zero downtime. Which three kubectl commands or approaches can achieve this? (Choose three.)

A developer is writing a CI/CD pipeline using Jenkins Declarative Pipeline. They want to ensure that sensitive credentials (e.g., API keys) are never exposed in console logs. Which two security practices should be implemented? (Choose two.)

You are writing a Dockerfile. Which instruction should you use to set the working directory for subsequent RUN, CMD, ENTRYPOINT, COPY, and ADD instructions?

You are writing a Dockerfile for a Python application. Which instruction should you use to install the dependencies from a requirements.txt file?

A developer needs to share a Docker image built from a Dockerfile with team members. Which command correctly builds the image and tags it as 'myapp:v1'?

A Kubernetes Deployment manages a set of identical pods. You update the container image to a new version. The rollout gets stuck. Which kubectl command should you use to view the rollout status and determine the cause?

A developer wants to run a container in the background with port mapping and a named volume. Which command accomplishes this?

In a Kubernetes cluster, you need to store non-sensitive configuration data (e.g., database hostname) that can be consumed by pods as environment variables. Which resource should you use?

Which TWO practices help prevent sensitive data exposure in a CI/CD pipeline? (Select two.)

A Kubernetes cluster runs a microservice that needs to read configuration values from a ConfigMap and sensitive database credentials from a Secret. The pod manifest references both resources. How should the Secret be mounted to avoid exposing sensitive data in logs or environment variables?

A developer uses Kubernetes and wants to expose a deployment named 'web-app' externally via a cloud load balancer. Which Service type should be used?

A developer is writing a Dockerfile for a Node.js application. The application uses environment variables for configuration. Which Dockerfile instruction should be used to set a default value for the NODE_ENV variable?

A developer is building a web application and wants to implement security best practices. Which TWO actions should be taken? (Choose two.)

Question 19mediummultiple choice
Read the full DNS explanation →

In a Kubernetes cluster, a developer needs to ensure that a set of pods can be accessed by other pods using a stable IP address and DNS name, even if pods are recreated. Which resource should be created?

In a Jenkins declarative pipeline, a stage named 'Deploy to Production' should only run after manual approval. Which directive should be used to achieve this?

Free account

Track your progress over time

Create a free account to save your results and see which topics improve across sessions.

Focused Application Deployment and Security sessions

Start a Application Deployment and Security only practice session

Every question in these sessions is drawn from the Application Deployment and Security domain — nothing else.

Related practice questions

Related 200-901 topic practice pages

Move into related areas when this topic feels solid.

Frequently asked questions

What does the 200-901 exam test about Application Deployment and Security?
Be able to build and debug a Docker image, choose the right Kubernetes volume for persistent data, and manage secrets safely in a pipeline. The single most important thing is diagnosing why a container or pod failed using the correct command before changing configuration.
How should I use these practice questions?
Select your answer before revealing the explanation. Then read why each option is right or wrong — this active recall approach builds retention far faster than re-reading notes.
Can I practise just Application Deployment and Security questions in a focused session?
Yes — the session launcher on this page draws every question from the Application Deployment and Security domain. Use a 10-question session first to gauge your baseline, then move to 20 or 30 once the weak spots are clear.
Where can I practise other 200-901 topics?
Use the topic links above to move to related areas, or go back to the 200-901 question bank to see all topics.
Are these real exam questions or dumps?
These are original practice questions written to test the same concepts the 200-901 exam covers. They are not copied from any real exam or dump site.