Courseiva
Cloud Application Security →mediumMultiple Choice

CCSP Cloud Application Security Practice Question

A cloud operations team is building a CI/CD pipeline that deploys container images to a managed Kubernetes cluster. Security policy requires that only images whose vulnerabilities have been scanned and approved can run. The team wants the cluster itself to refuse any pod that references an unapproved image, even if the pipeline is bypassed. Which mechanism should they implement?

⚠ Common exam trap

The trap here is assuming that scanning images in the registry or pipeline is equivalent to blocking unapproved pods from running in the cluster.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Configure a Kubernetes admission controller with a policy engine, such as Open Policy Agent Gatekeeper, to reject pods referencing images that lack the approved scan attestation.

The requirement is preventive enforcement at the cluster level, independent of the deployment channel. A Kubernetes admission controller backed by a policy engine intercepts pod creation and rejects any manifest that does not carry the approved scan attestation. Registry scanning, pipeline gates, and audit alerts each leave a path for an unapproved pod to run, so they cannot satisfy the policy as written.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Enable image vulnerability scanning in the container registry and configure the registry to block pulls of images that exceed the severity threshold.

    Why it's wrong here

    Registry-side scanning and pull blocking do prevent unapproved images from being downloaded, but they do not stop a pod that references an image already cached on the node or pulled from a different registry. The scenario demands that the cluster refuse the pod itself, so a registry control alone leaves a gap when the image is reachable through another path or already present locally.

  • ✓

    Configure a Kubernetes admission controller with a policy engine, such as Open Policy Agent Gatekeeper, to reject pods referencing images that lack the approved scan attestation.

    Why this is correct

    An admission controller with a policy engine evaluates every pod creation request against policy before the object is persisted, so a pod referencing an image without the required scan attestation is rejected by the cluster regardless of how the manifest was submitted. This enforces the control at the platform layer rather than relying on the pipeline, which is exactly what the scenario requires.

  • ✗

    Enable Kubernetes audit logging and forward events to a SIEM so that alerts fire when pods with unapproved images are created.

    Why it's wrong here

    Audit logging records that a pod was created and can trigger an alert, but it is detective, not preventive. The unapproved workload still runs and may execute malicious code before anyone responds. The scenario explicitly requires the cluster to refuse the pod, so a monitoring-only control does not meet the stated security policy.

  • ✗

    Add a policy check stage to the CI/CD pipeline that fails the build when the scanned image contains vulnerabilities above the threshold.

    Why it's wrong here

    A pipeline policy stage only governs deployments that flow through that pipeline. If a developer applies a manifest directly with kubectl or another pipeline is introduced, the check is bypassed entirely. The requirement that the cluster refuse unapproved pods even when the pipeline is bypassed is not satisfied by a build-time gate.

About these practice questions

One of 934 original CCSP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.