Courseiva

KCNA Cloud Native Application Delivery Practice Question

Which THREE of the following practices are essential for a secure cloud native CI/CD pipeline?

⚠ Common exam trap

CNCF often tests the misconception that storing secrets in plain text is acceptable if the pipeline is 'internal' or 'trusted,' but the KCNA exam emphasizes that secrets must never be stored in plain text in any CI/CD configuration.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Sign container images and verify signatures during deployment

Option A is correct because signing container images (e.g., with Sigstore Cosign or Docker Content Trust/Notary) and verifying those signatures at deploy time ensures only trusted, untampered artifacts are admitted, protecting against supply-chain tampering. Option D is correct because scanning images for known CVEs (e.g., with Trivy, Grype, or Clair) before deployment catches vulnerable base images and dependencies early, preventing exploitable workloads from reaching production. Option E is correct because applying least-privilege IAM roles to pipeline components limits the blast radius if a build step or runner is compromised, granting each stage only the permissions it needs. Option B is wrong because storing secrets in plain text in pipeline configuration exposes credentials to anyone with repo or log access; secrets should be kept in a managed vault or secret store and injected at runtime. Option C is wrong because a single long-lived service account shared across all pipeline steps violates least privilege and separation of duties, and long-lived credentials increase the risk and impact of credential theft.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Sign container images and verify signatures during deployment

    Why this is correct

    Signing images at build time and verifying signatures at admission ensures only artefacts produced by trusted pipeline identities reach the cluster, blocking tampered or substituted images. This satisfies the supply-chain integrity requirement of a secure cloud-native CI/CD pipeline.

  • ✗

    Store secrets in plain text in the pipeline configuration

    Why it's wrong here

    Plain-text secrets in pipeline configuration expose credentials to anyone with repository or log access, defeating secret management. It is tempting for quick debugging, but the essential practise is storing secrets in a dedicated vault and injecting them at runtime.

  • ✗

    Use a single long-lived service account for all pipeline steps

    Why it's wrong here

    A single long-lived service account shared across all pipeline steps removes per-step least privilege and makes credential rotation or revocation impossible without breaking every job. It is tempting to reduce configuration overhead, but the essential practise is short-lived, scoped credentials per pipeline stage.

  • ✓

    Scan container images for vulnerabilities before deployment

    Why this is correct

    Scanning images for known CVEs before deployment catches vulnerable base images and dependencies while they are still cheap to fix, preventing flawed artefacts from reaching production. This satisfies the pipeline's requirement to gate on vulnerability findings before release.

  • ✓

    Apply least-privilege IAM roles to pipeline components

    Why this is correct

    Least-privilege IAM roles bound to pipeline service accounts limit blast radius if a build agent or credential is compromised, restricting what an attacker can read or deploy. This satisfies the pipeline's requirement to constrain permissions for its own components.

Quick reference

AAA Protocol Comparison

ProtocolPort(s)EncryptionTransportPrimary Use
RADIUS1812 / 1813Password onlyUDPNetwork access control
TACACS+49Full packetTCPDevice administration
Diameter3868Full sessionTCP / SCTPCarrier / mobile networks
802.1X—EAP-basedLayer 2Port-based access control

TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.

About these practice questions

One of 930 original KCNA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This KCNA practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the KCNA exam.