Courseiva
hardMultiple Choice

CV0-004 Practice Question: Deploying a containerized microservices…

A company is deploying a containerized microservices architecture on Azure Kubernetes Service (AKS). The security team requires that all container images are scanned for vulnerabilities before deployment. Which deployment approach should the DevOps team implement to ensure only approved images are used?

⚠ Common exam trap

Test-takers frequently confuse image signing (e.g., Docker Content Trust or Notary) with vulnerability scanning, assuming that signing alone ensures security, but signing only verifies image origin and integrity, not the presence of vulnerabilities.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Enable Azure Container Registry tasks for automatic vulnerability scanning and enforce with Azure Policy.

Azure Container Registry (ACR) Tasks can automatically scan images for vulnerabilities using Microsoft Defender for Cloud, and Azure Policy can enforce that only images from approved registries or with passing scan results are deployed to AKS. This ensures that all container images are scanned before deployment and that only compliant images are used, meeting the security team's requirement.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Store all images in a private registry without any scanning.

    Why it's wrong here

    A private registry controls image provenance but performs no vulnerability analysis, so unscanned images still reach AKS. It is tempting because private registries restrict who can pull images, and one would be correct as a storage and access-control layer once scanning is added to the pipeline.

  • ✗

    Use Docker Content Trust to sign images and verify signatures during deployment.

    Why it's wrong here

    Docker Content Trust verifies publisher signatures and image integrity, but it does not detect known CVEs inside an image. It is tempting because signing sounds like approval, and it would be correct when the requirement is to prove an image came from a trusted publisher and was not tampered with.

  • ✓

    Enable Azure Container Registry tasks for automatic vulnerability scanning and enforce with Azure Policy.

    Why this is correct

    Azure Container Registry tasks scan images automatically on push, while Azure Policy for AKS enforces admission control, blocking any image lacking a passing scan before it reaches a node. This combination satisfies the requirement that only approved, vulnerability-scanned images are deployed, rather than merely alerting after deployment.

  • ✗

    Deploy an admission controller that checks image signatures only.

    Why it's wrong here

    Signature verification confirms provenance, not the presence of known CVEs, so unsigned-but-vulnerable images pass and the scanning requirement goes unmet. Admission controllers are the right mechanism for enforcing policy at deploy time, and signature checks would suffice where the mandate is supply-chain integrity rather than vulnerability scanning.

About these practice questions

One of 834 original CV0-004 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CV0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CV0-004 exam.