Courseiva

CCSP Cloud Application Security Practice Question

A cloud application uses a microservices architecture deployed on Kubernetes. The security team wants to enforce that only signed container images from a trusted registry can be deployed to the cluster. Which Kubernetes feature should be used to achieve this?

⚠ Common exam trap

It's easy for candidates to confuse access control (RBAC) or network segmentation (Network policies) with image integrity enforcement, which requires an admission controller that can verify cryptographic signatures.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Admission controllers with image signature verification

To enforce that only signed container images from a trusted registry are deployed, an admission controller with image signature verification is required. This controller validates the signature of the image before allowing the pod to be created. Tools like OPA Gatekeeper or Sigstore's policy controller can be configured to check signatures against trusted public keys. This ensures supply chain security and prevents unauthorized or tampered images from running in the cluster.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Pod security policies

    Why it's wrong here

    Pod security policies (deprecated in Kubernetes 1.21 and replaced by Pod Security Admission) define security contexts for pods, such as running as non-root or restricting volume types. They do not validate container image signatures. While they are part of a defense-in-depth strategy, they cannot enforce that only signed images from a trusted registry are deployed. A different mechanism is needed for image verification.

  • ✗

    Role-based access control (RBAC)

    Why it's wrong here

    RBAC controls who can perform actions on Kubernetes resources, such as creating pods or deployments. It does not inspect the content of the pod specification, including the container image. While RBAC can restrict which users or service accounts can deploy, it cannot enforce image signing. An admission controller is required to validate image signatures at deployment time.

  • ✓

    Admission controllers with image signature verification

    Why this is correct

    Admission controllers intercept requests to the Kubernetes API server before objects are persisted. By integrating an admission controller that verifies image signatures, such as the Open Policy Agent (OPA) Gatekeeper with a signature verification policy or the Sigstore policy controller, you can enforce that only images signed by trusted keys are admitted. This directly meets the requirement to allow only signed images from a trusted registry.

  • ✗

    Network policies

    Why it's wrong here

    Network policies control traffic flow between pods, not image integrity. They are used to segment the network and restrict communication, which is important for microservices security but does not enforce image signing. To ensure only signed images are deployed, you need an admission controller that validates image signatures. Network policies alone cannot prevent unsigned or malicious images from running in the cluster.

About these practice questions

Courseiva writes every CCSP question from scratch — 934 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.