CCSP Cloud Platform and Infrastructure Security Practice Question
A security engineer is reviewing container image security. Which of the following practices best ensures that a container image has not been tampered with and originates from a trusted source?
⚠ Common exam trap
The trap is equating vulnerability scanning or using minimal base images with integrity verification; only cryptographic signing and verification provide tamper-evidence and provenance.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Signing the image with Cosign and verifying it at deployment
Signing a container image with Cosign and verifying it at deployment ensures integrity and provenance by cryptographically binding the image to a trusted signer. Cosign uses public-key cryptography to sign the image digest, and verification at deployment (e.g., via admission controllers) ensures only signed images run. This directly addresses tampering and trusted source requirements.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Scanning the image with Trivy for CVEs
Why it's wrong here
Trivy detects known vulnerable packages inside an image; it cannot verify provenance or detect tampering, since it never checks a signature against a trusted publisher. It is tempting because CVE scanning is a core registry pipeline control, and would be correct when the requirement is identifying outdated libraries before deployment.
- ✗
Using a minimal base image like Alpine
Why it's wrong here
Alpine reduces the attack surface by shipping fewer packages, but a minimal image carries no cryptographic proof of origin and can be tampered with identically. It is tempting because smaller base images are a recognised hardening practise, and would be correct when the goal is limiting exploitable components rather than verifying authenticity.
- ✗
Setting the image tag to :latest
Why it's wrong here
The :latest tag is a mutable pointer, so a rebuilt or replaced image resolves to the same reference, giving no integrity guarantee or publisher identity. It is tempting for convenience in development, and would be correct only where automatic upgrades to the newest build are wanted, not provenance verification.
- ✓
Signing the image with Cosign and verifying it at deployment
Why this is correct
Cosign applies a cryptographic signature tied to the publisher's private key, and verification at deployment rejects any image whose digest or signature fails validation. This satisfies the tamper-evidence and trusted-origin constraint, since unsigned or altered images cannot pass admission.
Quick reference
Asymmetric Encryption Algorithm Comparison
| Algorithm | Key Exchange | Signatures | Equivalent Security Key | Notes |
|---|---|---|---|---|
| RSA-3072 | Yes | Yes | 128-bit | Widely deployed; slow for bulk data |
| ECDSA P-256 | No | Yes | 128-bit | Fast signatures; standard TLS certs |
| ECDH / ECDHE | Yes | No | 128-bit | Perfect forward secrecy in TLS 1.3 |
| DH / DHE | Yes | No | 128-bit (3072-bit key) | Replaced by ECDHE in modern TLS |
| Ed25519 | No | Yes | ~128-bit | SSH keys, modern PKI |
Go deeper
Related to this question
About these practice questions
Courseiva writes every CCSP question from scratch — 934 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.