CAS-004 Security Architecture Practice Question
A software company wants to ensure that every container image deployed to production is free of known critical vulnerabilities and is cryptographically signed by its build pipeline. The security architect must implement controls that verify the signature and vulnerability status before the container runtime starts the image. Which of the following should the architect implement?
⚠ Common exam trap
The trap here is assuming that registry scanning alone enforces security, when without an admission controller the scan results do not block deployment.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
A Kubernetes admission controller that validates image signatures and vulnerability scan results before allowing a pod to run.
The requirement is to verify image signatures and vulnerability status before the container runtime starts the image. A Kubernetes admission controller enforces these checks at pod creation, rejecting non-compliant images. SAST analyzes code, registry scanning only alerts, and runtime agents act after startup, so none provide the required pre-runtime enforcement.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
A container image scanner in the registry with automated alerts to the security team.
Why it's wrong here
Scanning images in the registry identifies vulnerabilities but only alerts; it does not block deployment or verify signatures. Without an admission controller to enforce the results, a vulnerable or unsigned image can still be pulled and started, so this does not satisfy the pre-runtime enforcement requirement.
- ✗
A runtime security agent that monitors container behavior and kills suspicious processes.
Why it's wrong here
A runtime agent detects and responds to malicious activity after the container is running, but it does not verify signatures or vulnerability status before startup. It is a detective and responsive control, not a preventive admission control, so it cannot stop an unsigned or vulnerable image from being deployed.
- ✓
A Kubernetes admission controller that validates image signatures and vulnerability scan results before allowing a pod to run.
Why this is correct
An admission controller intercepts pod creation and can reject images that lack a valid signature or that contain critical vulnerabilities, enforcing policy before the runtime starts the container. This directly meets the requirement to verify signature and vulnerability status at deployment time.
- ✗
A static application security testing (SAST) tool integrated into the CI pipeline.
Why it's wrong here
SAST analyzes source code for vulnerabilities but does not scan container images, verify cryptographic signatures, or enforce admission decisions at the runtime. It operates earlier in the lifecycle and cannot prevent an unsigned or vulnerable image from being deployed, so it fails the stated requirement.
Go deeper
Related to this question
About these practice questions
One of 973 original CAS-005 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.