KCNA Cloud Native Application Delivery Practice Question
Which THREE of the following practices are essential for a secure cloud native CI/CD pipeline?
⚠ Common exam trap
CNCF often tests the misconception that storing secrets in plain text is acceptable if the pipeline is 'internal' or 'trusted,' but the KCNA exam emphasizes that secrets must never be stored in plain text in any CI/CD configuration.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Sign container images and verify signatures during deployment
Option A is correct because signing container images (e.g., with Sigstore Cosign or Docker Content Trust/Notary) and verifying those signatures at deploy time ensures only trusted, untampered artifacts are admitted, protecting against supply-chain tampering. Option D is correct because scanning images for known CVEs (e.g., with Trivy, Grype, or Clair) before deployment catches vulnerable base images and dependencies early, preventing exploitable workloads from reaching production. Option E is correct because applying least-privilege IAM roles to pipeline components limits the blast radius if a build step or runner is compromised, granting each stage only the permissions it needs. Option B is wrong because storing secrets in plain text in pipeline configuration exposes credentials to anyone with repo or log access; secrets should be kept in a managed vault or secret store and injected at runtime. Option C is wrong because a single long-lived service account shared across all pipeline steps violates least privilege and separation of duties, and long-lived credentials increase the risk and impact of credential theft.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Sign container images and verify signatures during deployment
Why this is correct
Signing images at build time and verifying signatures at admission ensures only artefacts produced by trusted pipeline identities reach the cluster, blocking tampered or substituted images. This satisfies the supply-chain integrity requirement of a secure cloud-native CI/CD pipeline.
- ✗
Store secrets in plain text in the pipeline configuration
Why it's wrong here
Plain-text secrets in pipeline configuration expose credentials to anyone with repository or log access, defeating secret management. It is tempting for quick debugging, but the essential practise is storing secrets in a dedicated vault and injecting them at runtime.
- ✗
Use a single long-lived service account for all pipeline steps
Why it's wrong here
A single long-lived service account shared across all pipeline steps removes per-step least privilege and makes credential rotation or revocation impossible without breaking every job. It is tempting to reduce configuration overhead, but the essential practise is short-lived, scoped credentials per pipeline stage.
- ✓
Scan container images for vulnerabilities before deployment
Why this is correct
Scanning images for known CVEs before deployment catches vulnerable base images and dependencies while they are still cheap to fix, preventing flawed artefacts from reaching production. This satisfies the pipeline's requirement to gate on vulnerability findings before release.
- ✓
Apply least-privilege IAM roles to pipeline components
Why this is correct
Least-privilege IAM roles bound to pipeline service accounts limit blast radius if a build agent or credential is compromised, restricting what an attacker can read or deploy. This satisfies the pipeline's requirement to constrain permissions for its own components.
Quick reference
AAA Protocol Comparison
| Protocol | Port(s) | Encryption | Transport | Primary Use |
|---|---|---|---|---|
| RADIUS | 1812 / 1813 | Password only | UDP | Network access control |
| TACACS+ | 49 | Full packet | TCP | Device administration |
| Diameter | 3868 | Full session | TCP / SCTP | Carrier / mobile networks |
| 802.1X | — | EAP-based | Layer 2 | Port-based access control |
TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.
Go deeper
Related to this question
About these practice questions
One of 930 original KCNA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This KCNA practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the KCNA exam.