Courseiva

CCSP Cloud Application Security Practice Question

A cloud security architect is designing a CI/CD pipeline for a containerized application. The requirement is that container images be cryptographically signed by the build system and that only images with valid signatures be admitted to the production Kubernetes cluster. Which combination of controls best achieves this?

⚠ Common exam trap

The trap here is treating vulnerability scanning or private registry access as equivalent to image signing and admission verification, when none of those establishes or checks cryptographic provenance.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Sign images with a key managed by the build system and enforce signature verification with an admission controller that rejects unsigned images.

Meeting the requirement needs two complementary controls: cryptographic signing at build time to prove provenance, and admission-time verification to reject unsigned or tampered images. Scanning, registry access controls, and caching address different concerns and cannot enforce signature validity when pods are scheduled.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Store images in a private registry and restrict registry access using IAM policies.

    Why it's wrong here

    Private registries and IAM policies limit who can push or pull images, but they do not verify cryptographic signatures at deployment. An image pulled from the private registry could still be tampered with or replaced, and admission would proceed without signature validation.

  • ✗

    Scan images for vulnerabilities during the build and block the pipeline if critical findings are detected.

    Why it's wrong here

    Vulnerability scanning improves image hygiene but does not cryptographically sign images or verify their provenance at admission. An attacker could still deploy a tampered or unsigned image directly to the cluster, so this control does not meet the stated requirement.

  • ✓

    Sign images with a key managed by the build system and enforce signature verification with an admission controller that rejects unsigned images.

    Why this is correct

    Cryptographic signing by the build system establishes provenance, and an admission controller that verifies signatures before allowing pod creation enforces the policy at deploy time. Together they ensure only trusted images run in production, satisfying both the signing and admission requirements.

  • ✗

    Enable image layer caching in the build system to speed up builds and reduce exposure to tampering.

    Why it's wrong here

    Layer caching affects build performance and does not provide any cryptographic assurance about image integrity or origin. It neither signs images nor enforces verification, so it fails to satisfy the requirement for signed images admitted only after validation.

About these practice questions

Courseiva writes every CCSP question from scratch — 934 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.