hardMultiple Select
CCSP Practice Question: A cloud security architect is designing a secure…
A cloud security architect is designing a secure CI/CD pipeline for a containerized application deployed on a Kubernetes cluster. The pipeline must ensure that only approved images are deployed. Which TWO of the following controls should be implemented? (Choose two.)
⚠ Common exam trap
ISC2 often tests the distinction between controls that prevent unauthorized images from being deployed (signing and admission control) versus controls that manage access or detect vulnerabilities but do not enforce approval at deployment time.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Configure the Kubernetes admission controller to reject pods that use unsigned images.
Option B is correct because a Kubernetes admission controller (e.g., via an admission webhook or policy engine like OPA Gatekeeper or Kyverno) can enforce at admission time that any Pod referencing an image without a valid signature is rejected, directly ensuring only approved images run on the cluster. Option E is correct because signing container images with a private key (e.g., using cosign/Notation with a key pair) and verifying those signatures before deployment establishes cryptographic provenance, so only images signed by the trusted key are treated as approved. Together, B and E implement the verify-at-admission and sign-at-build halves of a supply-chain control that guarantees only approved images are deployed. Option A is not correct because RBAC on the registry controls who may push images, but it does not verify that deployed images are approved or untampered. Option C is not correct because network policies only restrict pod-to-pod traffic and have no bearing on image approval. Option D is not correct because vulnerability scanning identifies known CVEs but does not enforce that only approved (signed/trusted) images are deployed.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Implement role-based access control (RBAC) to restrict who can push images to the registry.
Why it's wrong here
Registry RBAC limits who may push images, yet an authorised pusher can still publish an unapproved image, so deployment approval is not enforced. It is tempting as least privilege, and would be correct if the risk were unauthorised registry writes rather than unapproved images.
- ✓
Configure the Kubernetes admission controller to reject pods that use unsigned images.
Why this is correct
A Kubernetes admission controller intercepts pod creation requests and rejects those referencing unsigned images, enforcing the approved-images-only constraint at deploy time. This prevents unverified container images from running in the cluster even if they bypass earlier pipeline stages.
- ✗
Use network policies to restrict pod-to-pod communication.
Why it's wrong here
Network policies segment pod-to-pod traffic at runtime and cannot determine whether a deployed image was approved. It is tempting because it hardens the cluster, and would be correct where the requirement is limiting lateral movement between workloads rather than controlling image admission.
- ✗
Scan all container images for vulnerabilities in the CI pipeline.
Why it's wrong here
Vulnerability scanning flags known CVEs but does not verify provenance or approval status, so unapproved images still pass. It is tempting because scanning is a genuine pipeline security control, and would be correct where the requirement is remediating vulnerable images rather than enforcing approval.
- ✓
Sign container images with a private key and verify signatures before deployment.
Why this is correct
Signing images with a private key and verifying signatures before deployment establishes cryptographic provenance, ensuring only images signed by trusted parties reach the cluster. This satisfies the approved-images-only constraint by authenticating image origin and integrity.
Quick reference
Access Control Model Comparison
| Model | Acronym | Who Controls Access? | Best For |
|---|---|---|---|
| Discretionary Access Control | DAC | Resource owner | Small teams, file shares |
| Mandatory Access Control | MAC | System / security labels | Classified govt / military |
| Role-Based Access Control | RBAC | Administrator (via roles) | Enterprise environments |
| Attribute-Based Access Control | ABAC | Policy engine (user + resource attributes) | Fine-grained, dynamic policies |
| Rule-Based Access Control | RuBAC | System rules / ACLs | Firewall rules, network ACLs |
Go deeper
Related to this question
About these practice questions
Courseiva writes every CCSP question from scratch — 934 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.