Courseiva

CCSP Cloud Platform and Infrastructure Security Practice Question

A cloud architect is designing a defense-in-depth strategy for a containerized application. Which THREE practices should be implemented to secure the container supply chain?

⚠ Common exam trap

CCSP often tests the misconception that encryption or scanning alone secures the supply chain, when the exam expects you to recognize that signing (integrity), immutable tags (reproducibility), and CVE scanning (vulnerability) are three distinct, complementary controls.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Sign images using Cosign

Option A is correct because signing images with Cosign (part of the Sigstore project) creates verifiable cryptographic signatures that let Kubernetes admission controllers or CI/CD pipelines confirm an image's provenance and integrity before deployment, preventing tampered or unauthorized images from entering the supply chain. Option D is correct because immutable tags such as a Git commit hash or digest guarantee that the exact audited artifact is deployed and cannot be silently overwritten, unlike mutable tags that can be repointed to different content. Option E is correct because scanning images with Trivy detects known CVEs in OS packages and language dependencies, enabling vulnerabilities to be caught and remediated early in the build pipeline. Option B is not appropriate because the 'latest' tag is mutable and non-deterministic, so builds become unreproducible and can pull in unvetted or vulnerable base images. Option C is not appropriate because running containers as root violates least privilege and dramatically increases the blast radius if a container is compromised; containers should run as a non-root user.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Sign images using Cosign

    Why this is correct

    Cosign signing creates a verifiable cryptographic attestation binding each image digest to a trusted publisher identity. This satisfies the supply-chain integrity constraint by enabling admission controllers to reject unsigned or tampered images before deployment, ensuring only artefacts built through approved pipelines reach the container runtime.

  • ✗

    Always use the 'latest' tag for base images

    Why it's wrong here

    The latest tag is mutable, so the base image pulled tonight may differ from the one tested, breaking reproducibility and integrity verification. Floating tags are acceptable for throwaway development builds, but a defence-in-depth supply chain requires pinned, digest-verified base images.

  • ✗

    Run containers with root privileges by default

    Why it's wrong here

    Root inside a container shares the host kernel, so a breakout or kernel exploit yields host-level control rather than confinement. Root is workable for trusted, isolated build jobs needing privileged operations, but runtime workloads should drop to a non-root user with minimal capabilities.

  • ✓

    Use immutable image tags (e.g., commit hash)

    Why this is correct

    Immutable tags such as commit hashes bind each deployment to an exact image digest, preventing tag mutation or accidental overwrites. This satisfies integrity by guaranteeing the artefact tested is the artefact deployed, closing a supply chain tampering vector.

  • ✓

    Scan images for CVEs with Trivy

    Why this is correct

    Scanning images with Trivy detects known CVEs in OS packages and language dependencies before deployment, satisfying the stem's supply-chain security requirement at the build and registry stages. This shifts vulnerability discovery left, preventing compromised or outdated base images from reaching production containers.

Quick reference

AAA Protocol Comparison

ProtocolPort(s)EncryptionTransportPrimary Use
RADIUS1812 / 1813Password onlyUDPNetwork access control
TACACS+49Full packetTCPDevice administration
Diameter3868Full sessionTCP / SCTPCarrier / mobile networks
802.1X—EAP-basedLayer 2Port-based access control

TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.

About these practice questions

This CCSP question is part of Courseiva's 934-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.