Courseiva

CCSP Cloud Platform and Infrastructure Security Practice Question

A security engineer is reviewing container image security. Which of the following practices best ensures that a container image has not been tampered with and originates from a trusted source?

⚠ Common exam trap

The trap is equating vulnerability scanning or using minimal base images with integrity verification; only cryptographic signing and verification provide tamper-evidence and provenance.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Signing the image with Cosign and verifying it at deployment

Signing a container image with Cosign and verifying it at deployment ensures integrity and provenance by cryptographically binding the image to a trusted signer. Cosign uses public-key cryptography to sign the image digest, and verification at deployment (e.g., via admission controllers) ensures only signed images run. This directly addresses tampering and trusted source requirements.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Scanning the image with Trivy for CVEs

    Why it's wrong here

    Trivy detects known vulnerable packages inside an image; it cannot verify provenance or detect tampering, since it never checks a signature against a trusted publisher. It is tempting because CVE scanning is a core registry pipeline control, and would be correct when the requirement is identifying outdated libraries before deployment.

  • ✗

    Using a minimal base image like Alpine

    Why it's wrong here

    Alpine reduces the attack surface by shipping fewer packages, but a minimal image carries no cryptographic proof of origin and can be tampered with identically. It is tempting because smaller base images are a recognised hardening practise, and would be correct when the goal is limiting exploitable components rather than verifying authenticity.

  • ✗

    Setting the image tag to :latest

    Why it's wrong here

    The :latest tag is a mutable pointer, so a rebuilt or replaced image resolves to the same reference, giving no integrity guarantee or publisher identity. It is tempting for convenience in development, and would be correct only where automatic upgrades to the newest build are wanted, not provenance verification.

  • ✓

    Signing the image with Cosign and verifying it at deployment

    Why this is correct

    Cosign applies a cryptographic signature tied to the publisher's private key, and verification at deployment rejects any image whose digest or signature fails validation. This satisfies the tamper-evidence and trusted-origin constraint, since unsigned or altered images cannot pass admission.

Quick reference

Asymmetric Encryption Algorithm Comparison

AlgorithmKey ExchangeSignaturesEquivalent Security KeyNotes
RSA-3072YesYes128-bitWidely deployed; slow for bulk data
ECDSA P-256NoYes128-bitFast signatures; standard TLS certs
ECDH / ECDHEYesNo128-bitPerfect forward secrecy in TLS 1.3
DH / DHEYesNo128-bit (3072-bit key)Replaced by ECDHE in modern TLS
Ed25519NoYes~128-bitSSH keys, modern PKI

About these practice questions

Courseiva writes every CCSP question from scratch — 934 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.