CCSP Cloud Application Security Practice Question
A cloud application uses a microservices architecture deployed on Kubernetes. The security team wants to enforce that only signed container images from a trusted registry can be deployed to the cluster. Which Kubernetes feature should be used to achieve this?
⚠ Common exam trap
It's easy for candidates to confuse access control (RBAC) or network segmentation (Network policies) with image integrity enforcement, which requires an admission controller that can verify cryptographic signatures.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Admission controllers with image signature verification
To enforce that only signed container images from a trusted registry are deployed, an admission controller with image signature verification is required. This controller validates the signature of the image before allowing the pod to be created. Tools like OPA Gatekeeper or Sigstore's policy controller can be configured to check signatures against trusted public keys. This ensures supply chain security and prevents unauthorized or tampered images from running in the cluster.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Pod security policies
Why it's wrong here
Pod security policies (deprecated in Kubernetes 1.21 and replaced by Pod Security Admission) define security contexts for pods, such as running as non-root or restricting volume types. They do not validate container image signatures. While they are part of a defense-in-depth strategy, they cannot enforce that only signed images from a trusted registry are deployed. A different mechanism is needed for image verification.
- ✗
Role-based access control (RBAC)
Why it's wrong here
RBAC controls who can perform actions on Kubernetes resources, such as creating pods or deployments. It does not inspect the content of the pod specification, including the container image. While RBAC can restrict which users or service accounts can deploy, it cannot enforce image signing. An admission controller is required to validate image signatures at deployment time.
- ✓
Admission controllers with image signature verification
Why this is correct
Admission controllers intercept requests to the Kubernetes API server before objects are persisted. By integrating an admission controller that verifies image signatures, such as the Open Policy Agent (OPA) Gatekeeper with a signature verification policy or the Sigstore policy controller, you can enforce that only images signed by trusted keys are admitted. This directly meets the requirement to allow only signed images from a trusted registry.
- ✗
Network policies
Why it's wrong here
Network policies control traffic flow between pods, not image integrity. They are used to segment the network and restrict communication, which is important for microservices security but does not enforce image signing. To ensure only signed images are deployed, you need an admission controller that validates image signatures. Network policies alone cannot prevent unsigned or malicious images from running in the cluster.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CCSP question from scratch — 934 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.