CCSP Cloud Platform and Infrastructure Security Practice Question
A DevOps team is building a container image for a cloud-native application. To minimize the attack surface and reduce the number of vulnerabilities, which type of base image should they use?
⚠ Common exam trap
The trap here is assuming 'smaller image = fewer vulnerabilities' and picking Alpine, when the exam is specifically testing that distroless removes even the shell and package manager, which Alpine retains.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
A distroless image
Distroless images contain only the application and its runtime dependencies — no package manager, shell, or OS utilities — which dramatically reduces the attack surface and the number of exploitable CVEs. Because there is no shell or package manager, attackers who gain code execution have far fewer tools to pivot or escalate with. This makes distroless the strongest choice when the explicit goal is minimizing vulnerabilities in a container image.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
A full distribution image like Ubuntu
Why it's wrong here
A full distribution image ships a complete userland — package manager, shells, compilers and services — all of which enter the image's attack surface and CVE count. It is tempting because it mirrors familiar server builds and eases troubleshooting, and would suit workloads needing distro-specific libraries or systemd, but it contradicts the minimise-vulnerabilities goal.
- ✗
An Alpine-based image
Why it's wrong here
Alpine's musl libc and BusyBox break glibc-linked binaries, so teams add compatibility layers or compile from source, enlarging the final image and reintroducing packages. It is tempting as a small, low-CVE base, and is correct for statically linked or musl-compatible workloads, but not universally for cloud-native builds.
- ✓
A distroless image
Why this is correct
A distroless image contains only the application and its runtime dependencies, omitting package managers, shells and other OS utilities. This directly minimises the attack surface and vulnerability count, satisfying the stem's requirement to reduce exploitable components in the container image.
- ✗
The 'latest' tag of any official image
Why it's wrong here
The 'latest' tag is mutable, so the same Dockerfile pulls different, unpinned layers over time, making vulnerability scanning and reproducibility impossible. It is tempting for convenience and automatic patch pickup, and would suit disposable development or test images, but production builds require digest-pinned, versioned tags.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CCSP question from scratch — 934 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.