KCNA Cloud Native Application Delivery Practice Question
A CI pipeline scans container images for vulnerabilities. The scan report shows a critical vulnerability in a base image layer. What is the most efficient way to remediate this issue?
⚠ Common exam trap
KCNA often tests the misconception that runtime security or patching running containers can substitute for rebuilding images, but the exam expects understanding of immutable infrastructure and root-cause remediation.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Update the base image to a patched version and rebuild the application image
The most efficient remediation for a vulnerability in a base image layer is to update the base image to a patched version and rebuild the application image. This addresses the root cause by replacing the vulnerable layer with a fixed one, ensuring that all future deployments are secure. It also aligns with immutable infrastructure practices, where containers are rebuilt rather than patched at runtime.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Update the base image to a patched version and rebuild the application image
Why this is correct
The vulnerability originates in the base image layer, so patching application code cannot remove it. Replacing the base image with a patched tag and rebuilding propagates the fix through every derived layer in one pass.
- ✗
Use a runtime security tool to block exploitation
Why it's wrong here
A runtime security tool blocks exploitation of known vulnerabilities during execution, but the CI pipeline scan identifies the vulnerability in the base image layer before deployment. Remediation requires rebuilding the image with a patched base layer, not runtime mitigation. This option is tempting because runtime tools effectively prevent exploitation in production environments, where patching the image is impractical, making them correct for post-deployment defence.
- ✗
Apply a security patch directly to the running container
Why it's wrong here
Patching a running container modifies only that ephemeral instance; the next restart or reschedule reverts to the vulnerable image layer, and the CI pipeline keeps producing affected images. It is tempting as a quick hotfix, but runtime patching suits emergency containment only. Rebuilding the image on an updated base resolves it durably.
- ✗
Ignore the vulnerability if the application code is not affected
Why it's wrong here
Ignoring the finding leaves the vulnerable base layer shipped in every image built from it, so the CVE remains exploitable regardless of application code paths. It is tempting when the vulnerable library is unreachable, but scanners and auditors still flag it. The correct approach rebuilds on a patched base image.
Go deeper
Related to this question
About these practice questions
Courseiva writes every KCNA question from scratch — 930 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
2 more ways this is tested on KCNA
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. Which THREE of the following are important security practices in a container image CI/CD pipeline?
medium- A.Hardcoding credentials in the image
- B.Running containers as root user
- ✓ C.Signing images to ensure integrity
- ✓ D.Using minimal base images to reduce attack surface
- ✓ E.Scanning images for vulnerabilities in the CI pipeline
Why C: Option C is correct because cryptographically signing container images (e.g., with Docker Content Trust/Notary or Sigstore cosign) lets the pipeline and runtime verify image integrity and provenance, preventing tampered or unauthorized images from being deployed. Option D is correct because using minimal base images (such as distroless, Alpine, or scratch) removes unnecessary packages, shells, and libraries, directly shrinking the attack surface and reducing the number of exploitable CVEs. Option E is correct because integrating vulnerability scanning (e.g., Trivy, Clair, or Grype) into the CI pipeline catches known CVEs in OS packages and dependencies before the image is published, enabling early remediation. Option A is wrong because hardcoding credentials in an image bakes secrets into layers where they can be extracted, violating secret-management best practices. Option B is wrong because running containers as root grants excessive privileges and increases the impact of a container escape, whereas least-privilege non-root users are recommended.
Variation 2. What is the purpose of container image scanning in a CI/CD pipeline?
easy- A.To ensure the image is stored in a registry
- B.To measure the image size and optimize it
- C.To verify the image tag follows naming conventions
- ✓ D.To identify security vulnerabilities in the image
Why D: Container image scanning in a CI/CD pipeline analyzes the image layers for known security vulnerabilities (CVEs) in OS packages, libraries, and application dependencies. It is a core DevSecOps practice that shifts security left, catching issues before the image is deployed to production.
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CNCF exam blueprint
This KCNA practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the KCNA exam.