Courseiva

CCSP Cloud Platform and Infrastructure Security Practice Question

A DevSecOps team is implementing a secure container supply chain. Which THREE practices should they adopt to ensure image integrity and trust from build to deployment?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Signing container images with Cosign

Option A is correct because Cosign (part of the Sigstore project) cryptographically signs container images using keyless or key-based signatures, producing a verifiable signature stored in the OCI registry that establishes provenance and integrity from build time. Option C is correct because an admission controller such as Kyverno (or OPA Gatekeeper) enforces policy at deploy time by verifying Cosign signatures before allowing a pod to be admitted, ensuring only trusted, signed images run in the cluster. Option E is correct because Trivy scans image layers against vulnerability databases (e.g., CVE feeds) and can fail CI/CD pipelines on critical findings, catching known flaws before an image is promoted. Option B is not appropriate because a private registry alone provides no integrity verification, and skipping scanning removes a key detection control. Option D is wrong because the mutable :latest tag offers no immutability or traceability, undermining supply-chain trust and reproducibility.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Signing container images with Cosign

    Why this is correct

    Cosign attaches cryptographic signatures to container images at build time, binding an image digest to a trusted signing identity. This gives downstream admission checks verifiable provenance, satisfying the integrity and trust requirement across the supply chain.

  • ✗

    Storing images in a private registry without scanning

    Why it's wrong here

    A private registry without scanning stores images but verifies nothing about their contents, so tampered or vulnerable layers pass through unchecked. Private registries are the right control when the requirement is restricting who can pull images, not establishing integrity or trust of what is inside them.

  • ✓

    Using admission controller (e.g., Kyverno) to verify signatures

    Why this is correct

    Kyverno acts as a Kubernetes admission controller, evaluating image signatures against trusted keys before admitting pods. This enforces the supply-chain constraint at deployment time, blocking any image lacking a valid Cosign signature from running in the cluster.

  • ✗

    Allowing any image with a :latest tag

    Why it's wrong here

    The :latest tag is mutable and unpinned, so the digest deployed cannot be traced to a reviewed build, defeating integrity verification. Floating tags suit rapid local development where reproducibility is irrelevant, but a supply chain requiring build-to-deployment trust needs immutable digest references instead.

  • ✓

    Scanning images for vulnerabilities using Trivy

    Why this is correct

    Trivy scanning detects known CVEs in OS packages and language dependencies, satisfying the requirement to identify vulnerable components before deployment. However, scanning alone addresses vulnerability discovery, not integrity or trust: it neither signs images nor verifies provenance. It complements, but cannot replace, cryptographic signing and attestation across the build-to-deploy pipeline.

About these practice questions

Courseiva writes every CCSP question from scratch — 934 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.