CGOA Related Practices Practice Question
Which practice represents the 'DevSecOps' aspect in a GitOps pipeline?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Enforcing policy constraints via OPA/Gatekeeper that validate manifests against security rules.
Policy-as-code tools like OPA/Gatekeeper allow for security policies to be versioned in Git and enforced automatically during the deployment process.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Conducting quarterly penetration tests.
Why it's wrong here
This is a compliance activity, not a pipeline-integrated DevSecOps practice.
- ✓
Enforcing policy constraints via OPA/Gatekeeper that validate manifests against security rules.
Why this is correct
This automates security policy enforcement within the delivery flow.
- ✗
Requiring a manual sign-off by a security officer for every deployment.
Why it's wrong here
This is a bottleneck and not automated.
- ✗
Storing secrets in plain text in the Git repository.
Why it's wrong here
This is a critical security failure.
About these practice questions
Courseiva writes every CGOA question from scratch — 325 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed August 2026 · checked against the official CNCF / Linux Foundation exam blueprint
This CGOA practice question is part of Courseiva's free CNCF / Linux Foundation certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CGOA exam.