Courseiva

KCNA Cloud Native Application Delivery Practice Question

A team uses a CI pipeline that builds a container image, scans it for vulnerabilities, and then pushes it to a registry. The scan reports a critical vulnerability in a library used by the application. The team wants to prevent images with critical vulnerabilities from being deployed to production. Which approach best enforces this policy in a Kubernetes-native way?

⚠ Common exam trap

The trap here is thinking that CI pipeline failure alone is sufficient; the question specifically asks for a Kubernetes-native enforcement mechanism, which points to admission control.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Use an admission controller such as OPA Gatekeeper to deny Pods that reference images with critical vulnerabilities.

An admission controller like OPA Gatekeeper can intercept Pod creation requests and evaluate them against policies. By integrating with vulnerability scan results, it can deny Pods that reference images with critical vulnerabilities. This enforces the policy at the cluster level, ensuring that even if an image bypasses CI checks, it cannot be deployed. CI pipeline failure is preventive but not Kubernetes-native enforcement.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Enable Pod Security Admission with the restricted profile to block vulnerable images.

    Why it's wrong here

    Pod Security Admission enforces Pod Security Standards, which focus on privilege escalation, host namespaces, and other runtime security contexts. It does not scan images for vulnerabilities. The restricted profile would not block an image based on its software libraries. Therefore, this option does not meet the requirement.

  • ✓

    Use an admission controller such as OPA Gatekeeper to deny Pods that reference images with critical vulnerabilities.

    Why this is correct

    OPA Gatekeeper is a Kubernetes admission controller that enforces policies at admission time. By integrating with a vulnerability scanner or using a pre-populated list of vulnerable images, it can deny Pod creation if the image has critical vulnerabilities. This enforces the policy directly in the cluster, preventing deployment regardless of the CI pipeline. It is a Kubernetes-native solution that provides a strong guardrail.

  • ✗

    Configure the CI pipeline to fail the build if the scan finds critical vulnerabilities.

    Why it's wrong here

    Failing the CI build prevents the image from being pushed to the registry, which is a valid control. However, it does not enforce the policy at deployment time. If an image is already in the registry or if the pipeline is bypassed, the image could still be deployed. The question asks for a Kubernetes-native way to prevent deployment, so this option is less robust than an admission controller.

  • ✗

    Use a Kubernetes NetworkPolicy to block traffic to Pods running vulnerable images.

    Why it's wrong here

    NetworkPolicy controls network traffic between Pods, not image vulnerabilities. It cannot inspect image contents or prevent Pod creation. While network policies are important for security, they do not address the requirement of blocking deployments based on vulnerability scans. This option misuses NetworkPolicy for an unrelated purpose.

About these practice questions

This KCNA question is part of Courseiva's 930-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CNCF exam blueprint

This KCNA practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the KCNA exam.