Courseiva

KCNA Cloud Native Application Delivery Practice Question

Which THREE of the following are important security practices in a container image CI/CD pipeline?

⚠ Common exam trap

KCNA often tests container security by including obvious anti-patterns (hardcoded credentials, running as root) as distractors — candidates must recognize these as insecure practices rather than legitimate options.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Signing images to ensure integrity

Option C is correct because cryptographically signing container images (e.g., with Docker Content Trust/Notary or Sigstore cosign) lets the pipeline and runtime verify image integrity and provenance, preventing tampered or unauthorized images from being deployed. Option D is correct because using minimal base images (such as distroless, Alpine, or scratch) removes unnecessary packages, shells, and libraries, directly shrinking the attack surface and reducing the number of exploitable CVEs. Option E is correct because integrating vulnerability scanning (e.g., Trivy, Clair, or Grype) into the CI pipeline catches known CVEs in OS packages and dependencies before the image is published, enabling early remediation. Option A is wrong because hardcoding credentials in an image bakes secrets into layers where they can be extracted, violating secret-management best practices. Option B is wrong because running containers as root grants excessive privileges and increases the impact of a container escape, whereas least-privilege non-root users are recommended.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Hardcoding credentials in the image

    Why it's wrong here

    Hardcoded credentials persist in image layers and registries, exposing secrets to anyone pulling the image. It tempts because it removes runtime configuration steps, but pipelines should inject secrets at runtime via vaults or environment variables.

  • ✗

    Running containers as root user

    Why it's wrong here

    Running containers as root grants any process inside the container full privileges on the host if it escapes, violating least privilege. It is tempting because root avoids permission errors during builds, and root is the default in many base images. Non-root execution with a read-only root filesystem is the correct practise for production pipelines.

  • ✓

    Signing images to ensure integrity

    Why this is correct

    Cryptographic signing with tools such as Cosign or Notation attaches a verifiable signature to the image digest, letting the admission controller reject tampered or unsigned artefacts before deployment. This satisfies the stem's integrity requirement, ensuring only images built by the trusted pipeline are admitted to the cluster.

  • ✓

    Using minimal base images to reduce attack surface

    Why this is correct

    Minimal base images such as distroless or Alpine ship fewer packages and libraries, shrinking the exploitable surface available to attackers. Fewer installed components mean fewer unpatched vulnerabilities reaching production, directly reducing the pipeline's overall risk.

  • ✓

    Scanning images for vulnerabilities in the CI pipeline

    Why this is correct

    Scanning images in CI catches known CVEs in base layers and dependencies before the image reaches a registry or runtime. This shifts vulnerability detection left, so flawed artefacts are blocked at build time rather than deployed, directly enforcing pipeline security.

About these practice questions

Courseiva writes every KCNA question from scratch — 930 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CNCF exam blueprint

This KCNA practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the KCNA exam.