KCNA Cloud Native Application Delivery Practice Question
Which THREE of the following are important security practices in a container image CI/CD pipeline?
⚠ Common exam trap
KCNA often tests container security by including obvious anti-patterns (hardcoded credentials, running as root) as distractors — candidates must recognize these as insecure practices rather than legitimate options.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Signing images to ensure integrity
Option C is correct because cryptographically signing container images (e.g., with Docker Content Trust/Notary or Sigstore cosign) lets the pipeline and runtime verify image integrity and provenance, preventing tampered or unauthorized images from being deployed. Option D is correct because using minimal base images (such as distroless, Alpine, or scratch) removes unnecessary packages, shells, and libraries, directly shrinking the attack surface and reducing the number of exploitable CVEs. Option E is correct because integrating vulnerability scanning (e.g., Trivy, Clair, or Grype) into the CI pipeline catches known CVEs in OS packages and dependencies before the image is published, enabling early remediation. Option A is wrong because hardcoding credentials in an image bakes secrets into layers where they can be extracted, violating secret-management best practices. Option B is wrong because running containers as root grants excessive privileges and increases the impact of a container escape, whereas least-privilege non-root users are recommended.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Hardcoding credentials in the image
Why it's wrong here
Hardcoded credentials persist in image layers and registries, exposing secrets to anyone pulling the image. It tempts because it removes runtime configuration steps, but pipelines should inject secrets at runtime via vaults or environment variables.
- ✗
Running containers as root user
Why it's wrong here
Running containers as root grants any process inside the container full privileges on the host if it escapes, violating least privilege. It is tempting because root avoids permission errors during builds, and root is the default in many base images. Non-root execution with a read-only root filesystem is the correct practise for production pipelines.
- ✓
Signing images to ensure integrity
Why this is correct
Cryptographic signing with tools such as Cosign or Notation attaches a verifiable signature to the image digest, letting the admission controller reject tampered or unsigned artefacts before deployment. This satisfies the stem's integrity requirement, ensuring only images built by the trusted pipeline are admitted to the cluster.
- ✓
Using minimal base images to reduce attack surface
Why this is correct
Minimal base images such as distroless or Alpine ship fewer packages and libraries, shrinking the exploitable surface available to attackers. Fewer installed components mean fewer unpatched vulnerabilities reaching production, directly reducing the pipeline's overall risk.
- ✓
Scanning images for vulnerabilities in the CI pipeline
Why this is correct
Scanning images in CI catches known CVEs in base layers and dependencies before the image reaches a registry or runtime. This shifts vulnerability detection left, so flawed artefacts are blocked at build time rather than deployed, directly enforcing pipeline security.
Go deeper
Related to this question
About these practice questions
Courseiva writes every KCNA question from scratch — 930 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CNCF exam blueprint
This KCNA practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the KCNA exam.