CCSP Cloud Platform and Infrastructure Security Practice Question
A company is deploying a microservices architecture on Kubernetes and wants to implement supply chain security. Which THREE of the following practices should be adopted?
⚠ Common exam trap
CCSP often tests whether candidates recognize that image signing alone is insufficient without enforcement — the trap is selecting signing and scanning but omitting the admission controller that actually blocks unsigned images at deploy time.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Signing container images with Cosign
Option A is correct because signing container images with Cosign (part of the Sigstore project) creates a verifiable cryptographic attestation of the image's provenance and integrity, which is a foundational supply chain security control. Option C is correct because scanning images for CVEs with Trivy detects known vulnerabilities in OS packages and application dependencies before deployment, enabling remediation prior to running workloads in the cluster. Option E is correct because an admission controller such as Kyverno can enforce policy at admission time, verifying Cosign signatures and rejecting unsigned or untrusted images so that only validated artifacts run in the cluster. Option B is incorrect because allowing all images from public registries removes provenance controls and exposes the cluster to untrusted or malicious images. Option D is incorrect because using the :latest tag is mutable and non-deterministic, preventing reliable signature verification and reproducible, auditable deployments.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Signing container images with Cosign
Why this is correct
Cosign signs container images with a private key, producing a verifiable signature stored in the registry alongside the image. This establishes provenance and integrity, letting downstream admission controls confirm the image was built by a trusted publisher before deployment.
- ✗
Allowing all images from public registries
Why it's wrong here
Pulling images from arbitrary public registries admits unvetted, potentially malicious artefacts into the cluster, directly undermining supply chain integrity. It is tempting because public registries offer convenience and broad image availability, and would be acceptable only where images are mirrored into a controlled, scanned private registry first.
- ✓
Scanning images for CVEs using Trivy
Why this is correct
Trivy scans image layers against vulnerability databases, detecting known CVEs in OS packages and language dependencies before deployment. This satisfies the supply chain requirement to identify and remediate vulnerable components prior to their admission into the cluster.
- ✗
Using the :latest tag for all images
Why it's wrong here
The :latest tag is mutable, so identical manifests can resolve to different images over time, defeating reproducibility and provenance verification. It is tempting because it removes version bookkeeping during development, and would be tolerable in throwaway test clusters where immutable digest pinning is not required.
- ✓
Configuring an admission controller like Kyverno to verify image signatures
Why this is correct
Kyverno admission control intercepts pod creation and validates the image's Cosign signature against trusted public keys, rejecting unsigned or tampered images. This enforces signature verification at deploy time, closing the gap between signing images and actually requiring signed images.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CCSP question from scratch — 934 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.