Courseiva
hardMultiple Choice

CCSP Practice Question: A DevOps team is deploying containers in a…

A DevOps team is deploying containers in a Kubernetes cluster. They need to ensure that container images are scanned for vulnerabilities before deployment. Which is the most effective approach?

⚠ Common exam trap

ISC2 often tests the distinction between pre-deployment controls (image scanning + admission) and runtime controls, so candidates mistakenly choose runtime tools (Option D) thinking they prevent vulnerabilities, when in fact runtime tools only detect active exploits after deployment.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Use a container registry with integrated vulnerability scanning and enforce admission controls.

Integrating vulnerability scanning into the container registry (e.g., using tools like Trivy, Clair, or Amazon ECR scanning) combined with admission controllers (e.g., OPA/Gatekeeper or Kyverno) allows automated scanning of images at rest and blocks deployments of non-compliant images before they enter the cluster. This shift-left approach ensures that only images passing security policies are admitted, preventing vulnerable images from reaching production.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Scan images manually after deployment.

    Why it's wrong here

    Scanning after deployment leaves vulnerable images already running in the cluster, so exploitation can occur before detection. It is tempting because manual scanning suits ad-hoc audits of a fixed image set, yet the stem demands pre-deployment gating, which admission controllers or CI pipeline scanning enforce.

  • ✓

    Use a container registry with integrated vulnerability scanning and enforce admission controls.

    Why this is correct

    Registry-integrated scanning inspects images at push time, and admission controllers block non-compliant images from ever reaching the cluster. This satisfies the stem's requirement for pre-deployment scanning, shifting enforcement to the admission layer rather than relying on post-deployment detection.

  • ✗

    Rely on the developer's assurance that images are secure.

    Why it's wrong here

    Developer assurance is unverified self-attestation, providing no evidence of scanning and no artefact to audit against. It tempts because it costs nothing and adds no pipeline latency, which suits low-risk prototypes. Admission controllers enforcing signed scan results are required to guarantee pre-deployment scanning in Kubernetes.

  • ✗

    Use a runtime security tool.

    Why it's wrong here

    Runtime security observes containers after they start, so a vulnerable image is already admitted and executing before detection occurs. It tempts because runtime tools catch live threats such as cryptomining, which suits post-deployment defence. Pre-deployment scanning needs admission control or a CI pipeline gate rejecting vulnerable images.

About these practice questions

This CCSP question is part of Courseiva's 934-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.