CCSP Cloud Platform and Infrastructure Security Practice Question
A DevSecOps team is implementing a secure container supply chain. Which THREE practices should they adopt to ensure image integrity and trust from build to deployment?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Signing container images with Cosign
Option A is correct because Cosign (part of the Sigstore project) cryptographically signs container images using keyless or key-based signatures, producing a verifiable signature stored in the OCI registry that establishes provenance and integrity from build time. Option C is correct because an admission controller such as Kyverno (or OPA Gatekeeper) enforces policy at deploy time by verifying Cosign signatures before allowing a pod to be admitted, ensuring only trusted, signed images run in the cluster. Option E is correct because Trivy scans image layers against vulnerability databases (e.g., CVE feeds) and can fail CI/CD pipelines on critical findings, catching known flaws before an image is promoted. Option B is not appropriate because a private registry alone provides no integrity verification, and skipping scanning removes a key detection control. Option D is wrong because the mutable :latest tag offers no immutability or traceability, undermining supply-chain trust and reproducibility.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Signing container images with Cosign
Why this is correct
Cosign attaches cryptographic signatures to container images at build time, binding an image digest to a trusted signing identity. This gives downstream admission checks verifiable provenance, satisfying the integrity and trust requirement across the supply chain.
- ✗
Storing images in a private registry without scanning
Why it's wrong here
A private registry without scanning stores images but verifies nothing about their contents, so tampered or vulnerable layers pass through unchecked. Private registries are the right control when the requirement is restricting who can pull images, not establishing integrity or trust of what is inside them.
- ✓
Using admission controller (e.g., Kyverno) to verify signatures
Why this is correct
Kyverno acts as a Kubernetes admission controller, evaluating image signatures against trusted keys before admitting pods. This enforces the supply-chain constraint at deployment time, blocking any image lacking a valid Cosign signature from running in the cluster.
- ✗
Allowing any image with a :latest tag
Why it's wrong here
The :latest tag is mutable and unpinned, so the digest deployed cannot be traced to a reviewed build, defeating integrity verification. Floating tags suit rapid local development where reproducibility is irrelevant, but a supply chain requiring build-to-deployment trust needs immutable digest references instead.
- ✓
Scanning images for vulnerabilities using Trivy
Why this is correct
Trivy scanning detects known CVEs in OS packages and language dependencies, satisfying the requirement to identify vulnerable components before deployment. However, scanning alone addresses vulnerability discovery, not integrity or trust: it neither signs images nor verifies provenance. It complements, but cannot replace, cryptographic signing and attestation across the build-to-deploy pipeline.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CCSP question from scratch — 934 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.