Courseiva
Security →mediumMultiple Select

CV0-004 Security Practice Question

A cloud architect is designing a container security strategy. Which TWO of the following should be implemented to secure containers? (Choose two.)

⚠ Common exam trap

CV0-004 often tests the misconception that hypervisor-level network ACLs secure containers, but containers require orchestration-aware policies like Kubernetes NetworkPolicies; also, candidates may think disabling security contexts simplifies management, but it removes essential isolation.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Runtime security monitoring for anomalous behavior

Option A (Runtime security monitoring for anomalous behavior) is correct because containers can be compromised after deployment, and runtime monitoring detects suspicious activity such as unexpected process execution, privilege escalation, or unauthorized file access, enabling rapid response to threats that static controls miss. Option C (Image scanning for vulnerabilities) is correct because container images often include outdated OS packages and libraries with known CVEs; scanning images in the CI/CD pipeline and registry before deployment prevents vulnerable artifacts from reaching production. Option B is wrong because disabling all security contexts removes controls like runAsNonRoot, readOnlyRootFilesystem, and dropped capabilities, weakening rather than strengthening container isolation. Option D is wrong because using the latest base images without scanning provides no assurance that known vulnerabilities are absent and can introduce unreviewed changes. Option E is wrong because network ACLs at the hypervisor level do not address container-specific risks such as image vulnerabilities or runtime compromise, and container network policy is typically enforced via Kubernetes NetworkPolicy or service mesh rather than hypervisor ACLs.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Runtime security monitoring for anomalous behavior

    Why this is correct

    Runtime security monitoring detects anomalous behaviour in running containers, such as unexpected process execution or privilege escalation, which static image scanning cannot catch. It satisfies the requirement to secure containers throughout their lifecycle, not only at build time.

  • ✗

    Disabling all security contexts in Kubernetes

    Why it's wrong here

    Disabling security contexts removes the very mechanisms — runAsNonRoot, read-only root filesystems, dropped capabilities — that restrict container privilege, weakening isolation. Security contexts are tempting because they look like hardening knobs, and they are correct when tightened with least-privilege values, not disabled outright.

  • ✓

    Image scanning for vulnerabilities

    Why this is correct

    Image scanning inspects container images for known vulnerabilities in packages and base layers before deployment, satisfying the requirement to secure containers at build time. It catches flaws that runtime monitoring would only observe after exploitation, so the two controls are complementary.

  • ✗

    Using the latest base images without scanning

    Why it's wrong here

    Pulling the newest base image tag without scanning imports unpatched vulnerabilities and defeats supply-chain assurance. Fresh images are tempting because currency suggests patched software, yet the correct practise is scanning images and pinning verified digests before deployment, not trusting recency alone.

  • ✗

    Implementing network ACLs at the hypervisor level

    Why it's wrong here

    Hypervisor ACLs filter traffic at the host virtual network layer, which container-to-container and pod-level flows bypass, leaving east-west traffic uncontrolled. They are tempting because ACLs are a familiar segmentation tool, and they are correct for isolating virtual machines or subnets, not for container network policy.

About these practice questions

Courseiva writes every CV0-004 question from scratch — 834 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This CV0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CV0-004 exam.