Courseiva

CCSP Cloud Platform and Infrastructure Security Practice Question

A company is deploying a microservices architecture on Kubernetes and wants to implement supply chain security. Which THREE of the following practices should be adopted?

⚠ Common exam trap

CCSP often tests whether candidates recognize that image signing alone is insufficient without enforcement — the trap is selecting signing and scanning but omitting the admission controller that actually blocks unsigned images at deploy time.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Signing container images with Cosign

Option A is correct because signing container images with Cosign (part of the Sigstore project) creates a verifiable cryptographic attestation of the image's provenance and integrity, which is a foundational supply chain security control. Option C is correct because scanning images for CVEs with Trivy detects known vulnerabilities in OS packages and application dependencies before deployment, enabling remediation prior to running workloads in the cluster. Option E is correct because an admission controller such as Kyverno can enforce policy at admission time, verifying Cosign signatures and rejecting unsigned or untrusted images so that only validated artifacts run in the cluster. Option B is incorrect because allowing all images from public registries removes provenance controls and exposes the cluster to untrusted or malicious images. Option D is incorrect because using the :latest tag is mutable and non-deterministic, preventing reliable signature verification and reproducible, auditable deployments.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Signing container images with Cosign

    Why this is correct

    Cosign signs container images with a private key, producing a verifiable signature stored in the registry alongside the image. This establishes provenance and integrity, letting downstream admission controls confirm the image was built by a trusted publisher before deployment.

  • ✗

    Allowing all images from public registries

    Why it's wrong here

    Pulling images from arbitrary public registries admits unvetted, potentially malicious artefacts into the cluster, directly undermining supply chain integrity. It is tempting because public registries offer convenience and broad image availability, and would be acceptable only where images are mirrored into a controlled, scanned private registry first.

  • ✓

    Scanning images for CVEs using Trivy

    Why this is correct

    Trivy scans image layers against vulnerability databases, detecting known CVEs in OS packages and language dependencies before deployment. This satisfies the supply chain requirement to identify and remediate vulnerable components prior to their admission into the cluster.

  • ✗

    Using the :latest tag for all images

    Why it's wrong here

    The :latest tag is mutable, so identical manifests can resolve to different images over time, defeating reproducibility and provenance verification. It is tempting because it removes version bookkeeping during development, and would be tolerable in throwaway test clusters where immutable digest pinning is not required.

  • ✓

    Configuring an admission controller like Kyverno to verify image signatures

    Why this is correct

    Kyverno admission control intercepts pod creation and validates the image's Cosign signature against trusted public keys, rejecting unsigned or tampered images. This enforces signature verification at deploy time, closing the gap between signing images and actually requiring signed images.

About these practice questions

Courseiva writes every CCSP question from scratch — 934 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.