Courseiva

KCNA Cloud Native Application Delivery Practice Question

A CI/CD pipeline includes image scanning. What is the primary security benefit of scanning container images in the CI phase?

⚠ Common exam trap

The trap here is conflating scanning with remediation — candidates pick 'automatically fixes vulnerabilities' because scanners suggest fixes, but the exam wants the preventive gate benefit, not auto-patching.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

It prevents vulnerable images from being deployed to production

Scanning images during CI catches known CVEs, misconfigurations, and embedded secrets before the artifact is pushed to a registry or promoted to production. By failing the pipeline on policy violations, teams create a gate that stops vulnerable images from ever reaching runtime environments, shifting security left. This is the core security value: prevention at the earliest feasible stage rather than detection after deployment.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    It reduces the time it takes to build images

    Why it's wrong here

    Scanning adds a pipeline stage and therefore does not shorten image build time; its security value is catching known vulnerabilities in base images and dependencies before deployment. Speed is tempting because faster feedback loops are a CI goal, but scanning trades a little time for early vulnerability detection.

  • ✗

    It automatically fixes vulnerabilities

    Why it's wrong here

    Scanning reports vulnerabilities; it does not patch or remediate them automatically, so images still require rebuilt, updated dependencies. Auto-fixing is tempting because remediation tooling exists, but scanning itself only identifies findings, and the security benefit is early detection before the image reaches production.

  • ✓

    It prevents vulnerable images from being deployed to production

    Why this is correct

    Scanning during CI catches known CVEs in base images and dependencies before the image reaches a registry, letting the pipeline fail the build and block promotion. This satisfies the stem's CI-phase constraint: remediation happens pre-deployment, so vulnerable artefacts never reach production clusters.

  • ✗

    It ensures that the image is built only once

    Why it's wrong here

    Scanning in CI detects vulnerable packages and misconfigurations before the image is published, enabling the build to fail early; it does not control how many times an image is built. Build-once is tempting because immutable, single-build artefacts aid reproducibility, but that is a pipeline design property, not the security benefit of scanning.

About these practice questions

Courseiva writes every KCNA question from scratch — 930 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CNCF exam blueprint

This KCNA practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the KCNA exam.