Courseiva
Cloud Application Security →mediumMultiple Choice

CCSP Cloud Application Security Practice Question

A healthcare SaaS company runs containerized microservices on Google Kubernetes Engine (GKE). The security team scans containers with a vulnerability scanner and finds that base images have several critical vulnerabilities. The container build process uses a Dockerfile that pulls the latest Ubuntu image from Docker Hub. The team wants to reduce the attack surface without delaying feature releases. What is the best approach?

⚠ Common exam trap

CCSP often tests the misconception that network controls or periodic rebuilds alone can mitigate image vulnerabilities, when the core issue is the base image and lack of continuous scanning.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Adopt minimal hardened base images and integrate vulnerability scanning into CI/CD

Adopting minimal hardened base images (e.g., distroless, Alpine, or UBI-minimal) reduces the number of packages and thus the attack surface, while integrating vulnerability scanning into CI/CD catches issues early without slowing releases. This directly addresses the root cause—vulnerable base images—and provides continuous feedback. The other options either don't fix the base image problem or are too disruptive.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Place a network security policy to restrict outbound traffic from pods

    Why it's wrong here

    Restricting pod egress traffic limits outbound connections but does nothing to remove vulnerable packages already present in the base image layers. It is tempting because it is a legitimate Kubernetes network control, and would be correct where the requirement is preventing data exfiltration or restricting which external services pods may reach.

  • ✗

    Schedule weekly automated rebuilds with the latest base image

    Why it's wrong here

    Rebuilding weekly still pulls the floating latest tag, so the same unpinned, vulnerable base is reintroduced and patched images may not be selected. It is tempting because automation feels like continuous patching, and would be correct where the base image tag is pinned and rebuilds deliberately pick up patched versions of that fixed image.

  • ✓

    Adopt minimal hardened base images and integrate vulnerability scanning into CI/CD

    Why this is correct

    Minimal hardened base images strip unnecessary packages, shrinking the exploitable surface, while CI/CD scanning catches vulnerabilities before release rather than after. Together they satisfy the stem's constraint of reducing attack surface without delaying feature releases, unlike pinning tags alone.

  • ✗

    Refactor all applications to use scratch as base image

    Why it's wrong here

    Scratch images contain no shell, package manager or libraries, so applications requiring a runtime cannot build or run without substantial rework, delaying releases. It is tempting because minimal images shrink attack surface, and would be correct for statically compiled binaries such as Go services that need no operating system userspace.

About these practice questions

Courseiva writes every CCSP question from scratch — 934 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.