Courseiva
Cloud Application Security →mediumMultiple Choice

CCSP Cloud Application Security Practice Question

A healthcare company runs a containerized patient portal on a managed Kubernetes service. Security policy requires that every container image be cryptographically verified as coming from the company's internal build pipeline before any pod is admitted to the cluster. The images are stored in a private OCI registry, and each build produces a signature using a private key held in a cloud key management service. Which mechanism should be implemented to enforce this policy at admission time?

⚠ Common exam trap

The trap here is assuming that vulnerability scanning or registry access controls prove image origin, when only cryptographic signature verification establishes provenance.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Configure an admission controller that validates image signatures against a trusted public key and rejects pods whose images are unsigned or signed by an untrusted key.

Enforcing image provenance requires cryptographic verification at admission time, not merely scanning or network controls. An admission controller that checks signatures against a trusted public key ensures that only images signed by the internal pipeline's private key are admitted. This directly ties the cluster's admission decision to the build pipeline's signing authority, satisfying the policy while leveraging the existing KMS key infrastructure.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Enable image vulnerability scanning in the registry and configure the cluster to pull only images with a CVSS score below a defined threshold.

    Why it's wrong here

    Vulnerability scanning assesses known flaws in image contents but does not establish provenance or cryptographic origin. An attacker could push a malicious image with no known vulnerabilities, and the scanner would not detect that it came from outside the build pipeline. This approach fails to meet the requirement of verifying that images originate from the internal pipeline.

  • ✗

    Use a mutating admission webhook to inject an init container that runs a checksum comparison of the image layers against a manifest stored in the registry.

    Why it's wrong here

    A checksum comparison against a manifest stored alongside the image does not prove authenticity because the manifest itself could be tampered with by anyone with registry write access. It also does not use the cryptographic signatures produced by the build pipeline. This approach adds complexity without delivering the required non-repudiable verification of image origin.

  • ✓

    Configure an admission controller that validates image signatures against a trusted public key and rejects pods whose images are unsigned or signed by an untrusted key.

    Why this is correct

    Admission controllers that verify cryptographic signatures on container images can block any pod whose image lacks a valid signature from the trusted public key. This directly enforces the policy before the pod is scheduled, ensuring only images from the internal pipeline are admitted. It works with the existing KMS-held private key because the corresponding public key is what the controller checks.

  • ✗

    Apply a network policy that restricts pod egress to only the private registry, preventing images from being pulled from any other source.

    Why it's wrong here

    Network policies control traffic flow but do not inspect image content or signatures. An attacker who can push to the private registry could still introduce an unsigned image, and the network policy would allow it. This does not provide cryptographic assurance of image origin or integrity, so it does not satisfy the admission-time verification requirement.

About these practice questions

This CCSP question is part of Courseiva's 934-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.