Courseiva
Cloud Application Security →mediumMultiple Choice

CCSP Cloud Application Security Practice Question

A healthcare company runs a containerized patient portal on a managed Kubernetes service. The security team needs to ensure that container images cannot be deployed if they contain known critical vulnerabilities. The build pipeline already produces an SBOM. Which control should be enforced at the admission layer to meet this requirement?

⚠ Common exam trap

The trap here is assuming that scanning images in CI alone is sufficient, when the scan result must be enforced at admission through signature or policy verification to actually prevent deployment.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Configure the cluster's admission controller to reject pods whose images are not signed by the organization's trusted cosign key, and run a vulnerability scan as part of the CI pipeline before signing.

Preventing deployment of vulnerable images requires a preventive control at admission that verifies images were scanned and approved. Signing images after a CI vulnerability scan and enforcing signature verification in the admission controller creates a cryptographic gate. Detection, private registries, and network controls do not evaluate image contents before scheduling, so they cannot block vulnerable workloads.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Configure network policies to limit pod-to-pod traffic and enable mutual TLS between all services in the cluster.

    Why it's wrong here

    Network policies and mTLS address lateral movement and confidentiality of service traffic. They have no bearing on whether an image contains known critical vulnerabilities at deploy time. While valuable for zero-trust segmentation, these controls do not inspect image contents, so they cannot prevent a vulnerable image from being scheduled.

  • ✗

    Enable a runtime security agent that alerts when a container executes a known malicious binary, and route alerts to the SOC for manual triage.

    Why it's wrong here

    Runtime detection alerts after a container is already running. It does not prevent deployment of images with known critical vulnerabilities; it only observes behavior. The stated requirement is to prevent deployment, so a detective control that depends on human triage fails to meet the preventive objective and leaves vulnerable workloads running until someone responds.

  • ✓

    Configure the cluster's admission controller to reject pods whose images are not signed by the organization's trusted cosign key, and run a vulnerability scan as part of the CI pipeline before signing.

    Why this is correct

    Admission control that enforces signature verification ensures only images approved by the CI pipeline (which includes vulnerability scanning) are admitted. Because the SBOM is already produced, integrating scanning into the pipeline and signing only clean images gives a verifiable, cryptographically enforced gate at deploy time, satisfying the requirement without relying on runtime detection.

  • ✗

    Restrict the cluster's image registry to an internal private registry and require developers to push images only to that registry.

    Why it's wrong here

    Using a private registry controls provenance and access but does not evaluate image contents for vulnerabilities. A developer could still push an image with critical CVEs, and the registry would accept it. The control is necessary for supply chain hygiene but insufficient to block vulnerable images at admission, so it does not satisfy the requirement.

About these practice questions

Courseiva writes every CCSP question from scratch — 934 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.