mediumMultiple Choice
CCSP Practice Question: A security team wants to ensure that only signed…
A security team wants to ensure that only signed container images are deployed in production. Which practice should they implement?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Image signing and verification
Signing container images with tools like Notary or Sigstore ensures the integrity and authenticity of images, preventing tampered or unauthorized images from being deployed.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Container image scanning with Trivy
Why it's wrong here
Trivy scans images for known vulnerabilities and misconfigurations; it does not verify cryptographic signatures or block unsigned images at admission. It tempts because scanning is a core supply-chain control, and it would be the right choice when the requirement is detecting vulnerable packages rather than enforcing provenance.
- ✗
Implementing a web application firewall (WAF)
Why it's wrong here
A WAF filters HTTP traffic to and from web applications; it cannot inspect image manifests or verify signatures before a container is scheduled. It tempts because WAFs enforce runtime traffic policy, and one would be correct if the requirement were blocking malicious requests rather than admission control.
- ✗
Using a private registry
Why it's wrong here
A private registry restricts who can pull images but does not verify signatures, so an unsigned image pushed by an authorised user still deploys. It tempts because registries are central to image distribution, and a private one is correct when the requirement is controlling network access and image availability.
- ✓
Image signing and verification
Why this is correct
Cryptographic signing lets the admission controller verify image provenance against a trusted key before deployment, rejecting tampered or unsigned artefacts. This directly enforces the stem's constraint that only signed images reach production, binding image integrity to the registry-to-runtime supply chain.
Go deeper
Related to this question
About these practice questions
This CCSP question is part of Courseiva's 934-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.