Courseiva
mediumMultiple Choice

CAS-004 Practice Question: A security analyst discovers that container…

A security analyst discovers that container images in the company's private registry lack signatures. The development team uses a script to build and push images. The analyst wants to ensure image integrity and prevent tampering. Which solution should the analyst recommend?

⚠ Common exam trap

Candidates often confuse access control (authentication/authorization) with integrity verification (signing/hashing) and mistakenly choose restricting access (Option B), thinking it prevents tampering, but it does not protect against insider threats or registry-level attacks.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Implement Docker Content Trust with a Notary server to require signatures on all images.

Docker Content Trust (DCT) integrates with a Notary server to enforce cryptographic signing of container images. When enabled, the Docker client will only pull, push, or run images that have been signed by trusted keys, ensuring image integrity and preventing tampering. This directly addresses the requirement to require signatures on all images in the private registry.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Implement Docker Content Trust with a Notary server to require signatures on all images.

    Why this is correct

    Docker Content Trust uses Notary to sign image tags, and the Docker client verifies those signatures before pull or run. Enforcing it in the build-and-push script blocks unsigned or tampered images from the private registry, directly satisfying the integrity requirement.

  • ✗

    Restrict registry access to only the build servers.

    Why it's wrong here

    Restricting registry access limits who can push but does not verify what was pushed, so a compromised build server can still upload tampered images. It is tempting because network controls are a familiar hardening step, and they would be correct for reducing the registry's attack surface rather than proving integrity.

  • ✗

    Use SSH keys to sign the image tarball before pushing.

    Why it's wrong here

    SSH keys sign arbitrary blobs, not OCI image manifests, so registries and admission controllers cannot verify the signature or detect layer tampering. It is tempting because the team already uses scripts and SSH keys, making it feel like a low-effort extension of existing tooling.

  • ✗

    Encrypt the image filesystem layer using AES-256.

    Why it's wrong here

    Encrypting layers with AES-256 protects confidentiality at rest but provides no origin verification, so a tampered image still decrypts and runs. Signing (for example with Notation or Cosign) is what detects tampering. Encryption is tempting because it sounds like integrity protection, but it is the right control for data-at-rest confidentiality requirements.

About these practice questions

This CAS-005 question is part of Courseiva's 973-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.