CCSP Cloud Security Operations Practice Question
A cloud security architect is evaluating vulnerability management solutions for a hybrid cloud environment. The team needs to scan both on-premises servers and cloud workloads without installing agents on every system. Which approach is most suitable for cloud workloads?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Agentless scanning via cloud APIs (CSPM)
Agentless scanning uses cloud APIs to assess vulnerabilities without requiring an agent on each instance. This is ideal for cloud workloads where agents may not be desired.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Agent-based scanning using a cloud-native service
Why it's wrong here
Agent-based scanning requires installing software on every system, directly contradicting the stated agentless requirement. It tempts because agents give deep, continuous visibility and are the standard choice when full host-level coverage is acceptable, but here that deployment overhead disqualifies it.
- ✗
Network vulnerability scanning from a remote scanner
Why it's wrong here
Remote network scanning reaches hosts over the network but cannot inspect cloud workloads lacking exposed interfaces, and often misses patching state inside instances. It tempts because it is agentless and works for on-premises servers, which is why it suits traditional data-centre scanning rather than cloud-native workloads.
- ✗
Container image scanning only
Why it's wrong here
Container image scanning covers only containerised artefacts, leaving virtual machines, serverless functions and host operating systems unscanned, so it cannot satisfy the hybrid cloud workload requirement. It tempts because it is agentless and cloud-native, and would be correct if the workloads were exclusively container images.
- ✓
Agentless scanning via cloud APIs (CSPM)
Why this is correct
Agentless scanning via cloud APIs queries the provider's control plane, so no software runs on each workload. This satisfies the stem's constraint of scanning cloud workloads without installing agents, unlike host-based tools that require per-system deployment.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CCSP question from scratch — 934 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.