SY0-701 Security Architecture Practice Question
A software development company is moving its CI/CD pipeline to a cloud environment. The security team wants to ensure that only authorized code can be deployed to production. They require that each build artifact be cryptographically signed, and that the signature be verified before deployment. Which of the following should be implemented to achieve this?
⚠ Common exam trap
The trap here is assuming that access controls or code analysis alone can ensure only authorized code is deployed, when cryptographic signing and verification are specifically required.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Code signing with a hardware security module (HSM) and signature verification in the deployment pipeline.
The correct answer is code signing with an HSM and signature verification in the deployment pipeline. This ensures that only artifacts signed with the protected private key are deployed, providing cryptographic assurance of authenticity and integrity. The other options improve security but do not implement the required signing and verification mechanism.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Static application security testing (SAST) integrated into the build process.
Why it's wrong here
SAST analyzes source code for vulnerabilities during development, but it does not sign artifacts or verify their authenticity before deployment. It helps improve code quality and security, but it cannot prevent unauthorized or tampered artifacts from being deployed if an attacker bypasses the pipeline. Thus, it does not meet the specific requirement for cryptographic signing and verification.
- ✗
Multi-factor authentication (MFA) for developers accessing the CI/CD system.
Why it's wrong here
MFA strengthens authentication for developers, reducing unauthorized access to the CI/CD system, but it does not cryptographically sign build artifacts or verify their integrity before deployment. An attacker who compromises a developer's session could still inject malicious code. Therefore, MFA alone does not satisfy the requirement for signed and verified artifacts.
- ✗
Role-based access control (RBAC) for the artifact repository.
Why it's wrong here
RBAC restricts who can access or modify artifacts in the repository, but it does not provide cryptographic proof of artifact integrity or authenticity. An attacker with sufficient privileges could still replace an artifact. Without signature verification, the deployment pipeline cannot distinguish authorized from unauthorized artifacts. Therefore, RBAC alone is insufficient for the stated requirement.
- ✓
Code signing with a hardware security module (HSM) and signature verification in the deployment pipeline.
Why this is correct
Code signing with an HSM ensures that build artifacts are signed with a protected private key, and signature verification in the deployment pipeline confirms authenticity and integrity before deployment. This directly meets the requirement that only authorized code can be deployed. The HSM protects the signing key from compromise, and verification prevents tampered or unauthorized artifacts from reaching production.
Go deeper
Related to this question
Learn chapter
Firewall Types and Deployment
Key term
HSM
An HSM (Hardware Security Module) is a dedicated hardware device that securely generates, stores, and manages cryptographic keys used to protect sensitive data.
Key term
Security
Security in IT is the practice of protecting systems, networks, and data from unauthorized access, damage, or theft.
About these practice questions
Courseiva writes every SY0-701 question from scratch — 1,030 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.