CAS-004 Security Architecture Practice Question
An organization is deploying a containerized application on Kubernetes and must enforce that only approved container images are allowed to run, and that containers cannot escalate privileges. Which combination of controls should the architect implement?
⚠ Common exam trap
CAS-005 often tests the misconception that runtime hardening tools like Seccomp/AppArmor or RBAC alone satisfy 'only approved images' requirements, when admission control plus image signing is the actual enforcement point.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Admission controllers with image signing and PodSecurityPolicy
Admission controllers are the Kubernetes mechanism that intercepts API server requests before objects are persisted, so they can reject pods that violate policy. Combined with image signing (e.g., via cosign/Notary or an admission webhook that verifies signatures), they enforce that only approved images run. PodSecurityPolicy (or its successor, Pod Security Admission with restricted/baseline profiles) blocks privilege escalation by restricting privileged containers, hostPath mounts, and capabilities.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Seccomp and AppArmor profiles with RBAC
Why it's wrong here
Seccomp and AppArmor restrict syscalls and file access, and RBAC governs API permissions, but none verifies image provenance or blocks privileged escalation flags. These suit hardening container runtime behaviour and cluster access, not enforcing an approved-image allowlist at admission.
- ✗
Kubernetes network policies and RBAC
Why it's wrong here
Network policies restrict pod traffic and RBAC governs API access, neither of which validates which images may run nor blocks privilege escalation inside a container. They are the right controls for east-west segmentation and user authorisation, not for admission control or capability restriction.
- ✓
Admission controllers with image signing and PodSecurityPolicy
Why this is correct
Admission controllers intercept API requests before pods are created, rejecting unsigned or unapproved images, while PodSecurityPolicy restricts privileged escalation and capability use. Together they enforce image provenance and prevent privilege escalation, matching both stem constraints.
- ✗
Container image scanning and network policies
Why it's wrong here
Scanning detects known vulnerabilities in images but does not gate deployment to approved images, and network policies only govern pod-to-pod traffic, not privilege escalation. These controls suit vulnerability management and traffic segmentation, not admission enforcement or preventing containers gaining elevated capabilities.
Go deeper
Related to this question
About these practice questions
This CAS-005 question is part of Courseiva's 973-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.