CCSP Cloud Platform and Infrastructure Security Practice Question
A cloud architect is designing a defense-in-depth strategy for a containerized application. Which THREE practices should be implemented to secure the container supply chain?
⚠ Common exam trap
CCSP often tests the misconception that encryption or scanning alone secures the supply chain, when the exam expects you to recognize that signing (integrity), immutable tags (reproducibility), and CVE scanning (vulnerability) are three distinct, complementary controls.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Sign images using Cosign
Option A is correct because signing images with Cosign (part of the Sigstore project) creates verifiable cryptographic signatures that let Kubernetes admission controllers or CI/CD pipelines confirm an image's provenance and integrity before deployment, preventing tampered or unauthorized images from entering the supply chain. Option D is correct because immutable tags such as a Git commit hash or digest guarantee that the exact audited artifact is deployed and cannot be silently overwritten, unlike mutable tags that can be repointed to different content. Option E is correct because scanning images with Trivy detects known CVEs in OS packages and language dependencies, enabling vulnerabilities to be caught and remediated early in the build pipeline. Option B is not appropriate because the 'latest' tag is mutable and non-deterministic, so builds become unreproducible and can pull in unvetted or vulnerable base images. Option C is not appropriate because running containers as root violates least privilege and dramatically increases the blast radius if a container is compromised; containers should run as a non-root user.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Sign images using Cosign
Why this is correct
Cosign signing creates a verifiable cryptographic attestation binding each image digest to a trusted publisher identity. This satisfies the supply-chain integrity constraint by enabling admission controllers to reject unsigned or tampered images before deployment, ensuring only artefacts built through approved pipelines reach the container runtime.
- ✗
Always use the 'latest' tag for base images
Why it's wrong here
The latest tag is mutable, so the base image pulled tonight may differ from the one tested, breaking reproducibility and integrity verification. Floating tags are acceptable for throwaway development builds, but a defence-in-depth supply chain requires pinned, digest-verified base images.
- ✗
Run containers with root privileges by default
Why it's wrong here
Root inside a container shares the host kernel, so a breakout or kernel exploit yields host-level control rather than confinement. Root is workable for trusted, isolated build jobs needing privileged operations, but runtime workloads should drop to a non-root user with minimal capabilities.
- ✓
Use immutable image tags (e.g., commit hash)
Why this is correct
Immutable tags such as commit hashes bind each deployment to an exact image digest, preventing tag mutation or accidental overwrites. This satisfies integrity by guaranteeing the artefact tested is the artefact deployed, closing a supply chain tampering vector.
- ✓
Scan images for CVEs with Trivy
Why this is correct
Scanning images with Trivy detects known CVEs in OS packages and language dependencies before deployment, satisfying the stem's supply-chain security requirement at the build and registry stages. This shifts vulnerability discovery left, preventing compromised or outdated base images from reaching production containers.
Quick reference
AAA Protocol Comparison
| Protocol | Port(s) | Encryption | Transport | Primary Use |
|---|---|---|---|---|
| RADIUS | 1812 / 1813 | Password only | UDP | Network access control |
| TACACS+ | 49 | Full packet | TCP | Device administration |
| Diameter | 3868 | Full session | TCP / SCTP | Carrier / mobile networks |
| 802.1X | — | EAP-based | Layer 2 | Port-based access control |
TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.
Go deeper
Related to this question
About these practice questions
This CCSP question is part of Courseiva's 934-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.