Courseiva
mediumMultiple Choice

CCSP Practice Question: A security team wants to ensure that only signed…

A security team wants to ensure that only signed container images are deployed in production. Which practice should they implement?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Image signing and verification

Signing container images with tools like Notary or Sigstore ensures the integrity and authenticity of images, preventing tampered or unauthorized images from being deployed.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Container image scanning with Trivy

    Why it's wrong here

    Trivy scans images for known vulnerabilities and misconfigurations; it does not verify cryptographic signatures or block unsigned images at admission. It tempts because scanning is a core supply-chain control, and it would be the right choice when the requirement is detecting vulnerable packages rather than enforcing provenance.

  • ✗

    Implementing a web application firewall (WAF)

    Why it's wrong here

    A WAF filters HTTP traffic to and from web applications; it cannot inspect image manifests or verify signatures before a container is scheduled. It tempts because WAFs enforce runtime traffic policy, and one would be correct if the requirement were blocking malicious requests rather than admission control.

  • ✗

    Using a private registry

    Why it's wrong here

    A private registry restricts who can pull images but does not verify signatures, so an unsigned image pushed by an authorised user still deploys. It tempts because registries are central to image distribution, and a private one is correct when the requirement is controlling network access and image availability.

  • ✓

    Image signing and verification

    Why this is correct

    Cryptographic signing lets the admission controller verify image provenance against a trusted key before deployment, rejecting tampered or unsigned artefacts. This directly enforces the stem's constraint that only signed images reach production, binding image integrity to the registry-to-runtime supply chain.

About these practice questions

This CCSP question is part of Courseiva's 934-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.