Courseiva
Cloud Security Operations →mediumMultiple Choice

CCSP Cloud Security Operations Practice Question

A cloud operations team is deploying a containerized workload on a managed Kubernetes service. They need to ensure that if a container image is discovered to contain a critical vulnerability, the running pods using that image are automatically replaced with a non-vulnerable version. Which mechanism BEST achieves this?

⚠ Common exam trap

The trap here is assuming that runtime detection or network isolation automatically remediates a vulnerable container image, when only an admission control policy combined with a deployment update actually replaces running pods with a patched image.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Configure an admission controller that rejects the vulnerable image tag and use a deployment strategy that replaces pods when the image tag is updated to a patched version.

Blocking the vulnerable image through an admission controller stops new pods from using it, and updating the deployment to a patched image tag triggers a rolling update that replaces existing pods. Together these enforce image policy and automatically converge the workload on the safe version, meeting the automatic replacement requirement without relying on manual intervention.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Use a network policy that isolates pods running the vulnerable image until the image is patched.

    Why it's wrong here

    Network policies control traffic flow between pods but do not replace or restart workloads. Isolating pods may reduce exposure but leaves the vulnerable containers running, and it does not address the requirement to automatically replace them. It also risks breaking application functionality without resolving the underlying vulnerability.

  • ✗

    Configure a pod disruption budget that prevents pods with vulnerabilities from being evicted during maintenance windows.

    Why it's wrong here

    Pod disruption budgets govern voluntary disruptions such as node drains, ensuring a minimum number of pods remain available. They do not detect vulnerabilities or replace pods, and in this scenario they would actually hinder replacement by limiting evictions. This mechanism is unrelated to vulnerability remediation.

  • ✓

    Configure an admission controller that rejects the vulnerable image tag and use a deployment strategy that replaces pods when the image tag is updated to a patched version.

    Why this is correct

    Admission controllers can block new pods that reference a denied image, while a rolling update triggered by changing the image tag replaces existing pods with the patched version. This combination prevents vulnerable images from being scheduled and ensures running workloads converge on the safe image without manual pod deletion, directly satisfying the automatic replacement requirement.

  • ✗

    Enable a runtime security agent that detects the vulnerability at runtime and sends an alert to the security team for manual remediation.

    Why it's wrong here

    A runtime agent that only alerts does not automatically replace pods; it relies on human intervention, which may be slow and inconsistent. The requirement is automatic replacement, so alerting alone is insufficient. Runtime detection is valuable for defense in depth but does not enforce image hygiene or trigger pod recreation by itself.

About these practice questions

This CCSP question is part of Courseiva's 934-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.