CCSP Cloud Application Security Practice Question
A cloud security engineer is reviewing the software development lifecycle for a team building a containerized application on a public cloud. The team wants to shift security left and reduce vulnerabilities in production images. Which two practices should be implemented to achieve this? (Choose two.)
⚠ Common exam trap
Candidates often confuse post-deployment controls like runtime detection or penetration testing with shift-left practices that prevent vulnerabilities earlier.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Integrate static application security testing (SAST) into the CI pipeline
Shifting security left means embedding security checks early in the development lifecycle. SAST finds code-level flaws at commit time, and container image scanning finds vulnerable packages at build time. Both prevent vulnerable artifacts from reaching production. Runtime detection, annual penetration tests, and private registries are valuable but operate after deployment or only control access, not vulnerability reduction.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Integrate static application security testing (SAST) into the CI pipeline
Why this is correct
SAST analyzes source code or binaries for security flaws early in the development process, before deployment. Integrating it into the CI pipeline ensures every commit is scanned, allowing developers to fix issues quickly. This directly supports shifting security left by catching vulnerabilities such as injection flaws or insecure cryptographic usage before they reach production images.
- ✗
Store container images in a private registry with access controls
Why it's wrong here
A private registry with access controls protects images from unauthorized access and tampering, which is a good supply chain control. However, it does not identify or remediate vulnerabilities within the images themselves. The question asks for practices that reduce vulnerabilities in production images, not just control who can access them.
- ✓
Scan container images for known vulnerabilities in the CI/CD pipeline
Why this is correct
Image scanning identifies known CVEs in base images and installed packages before deployment. Running scans in the CI/CD pipeline prevents vulnerable images from being promoted to production. This is a core shift-left practice because it catches issues at build time rather than after deployment, reducing the attack surface of running containers.
- ✗
Perform a penetration test of the production environment annually
Why it's wrong here
Annual penetration testing is a point-in-time assessment that occurs after deployment and provides limited coverage between tests. It does not integrate into the development workflow or prevent vulnerable code from being built. While useful for compliance and identifying gaps, it is not a shift-left practice that continuously reduces vulnerabilities in production images.
- ✗
Enable runtime threat detection in the production Kubernetes cluster
Why it's wrong here
Runtime threat detection monitors running workloads for malicious behavior, but it operates after deployment. While valuable, it does not shift security left; it detects issues that have already reached production. The scenario specifically asks for practices that reduce vulnerabilities before production, so runtime detection addresses a different phase of the lifecycle.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CCSP question from scratch — 934 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.