Courseiva
Cloud Security Operations →mediumMultiple Choice

CCSP Cloud Security Operations Practice Question

A cloud security architect is evaluating vulnerability management solutions for a hybrid cloud environment. The team needs to scan both on-premises servers and cloud workloads without installing agents on every system. Which approach is most suitable for cloud workloads?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Agentless scanning via cloud APIs (CSPM)

Agentless scanning uses cloud APIs to assess vulnerabilities without requiring an agent on each instance. This is ideal for cloud workloads where agents may not be desired.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Agent-based scanning using a cloud-native service

    Why it's wrong here

    Agent-based scanning requires installing software on every system, directly contradicting the stated agentless requirement. It tempts because agents give deep, continuous visibility and are the standard choice when full host-level coverage is acceptable, but here that deployment overhead disqualifies it.

  • ✗

    Network vulnerability scanning from a remote scanner

    Why it's wrong here

    Remote network scanning reaches hosts over the network but cannot inspect cloud workloads lacking exposed interfaces, and often misses patching state inside instances. It tempts because it is agentless and works for on-premises servers, which is why it suits traditional data-centre scanning rather than cloud-native workloads.

  • ✗

    Container image scanning only

    Why it's wrong here

    Container image scanning covers only containerised artefacts, leaving virtual machines, serverless functions and host operating systems unscanned, so it cannot satisfy the hybrid cloud workload requirement. It tempts because it is agentless and cloud-native, and would be correct if the workloads were exclusively container images.

  • ✓

    Agentless scanning via cloud APIs (CSPM)

    Why this is correct

    Agentless scanning via cloud APIs queries the provider's control plane, so no software runs on each workload. This satisfies the stem's constraint of scanning cloud workloads without installing agents, unlike host-based tools that require per-system deployment.

About these practice questions

Courseiva writes every CCSP question from scratch — 934 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.