Courseiva
mediumMultiple Choice

CCSP Practice Question: Uses a continuous integration/continuous…

An organization uses a continuous integration/continuous deployment (CI/CD) pipeline to deploy infrastructure as code. The security team wants to ensure that all cloud resources comply with internal security policies before deployment. Which of the following is the MOST effective method to enforce this?

⚠ Common exam trap

CCSP often tests the shift-left principle — candidates pick post-deployment scanning or manual review because they sound thorough, but the exam wants preventive, automated enforcement inside the pipeline.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Run automated policy compliance checks as part of the CI/CD pipeline.

Running automated policy compliance checks inside the CI/CD pipeline enforces security policies before resources are deployed, shifting compliance left. Tools like Terraform Sentinel, Checkov, or OPA/Conftest evaluate the IaC against policy and fail the pipeline on violations, preventing non-compliant infrastructure from ever reaching the cloud. This is the most effective because it is preventive, automated, and repeatable.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Restrict the IAM permissions of developers to only approved roles.

    Why it's wrong here

    Restricting developer IAM permissions limits which actions identities can perform, but it cannot inspect the configuration declared in templates, so non-compliant resources still deploy. Least-privilege IAM is correct for limiting blast radius, not for policy validation of infrastructure as code.

  • ✓

    Run automated policy compliance checks as part of the CI/CD pipeline.

    Why this is correct

    Embedding automated policy checks in the CI/CD pipeline evaluates infrastructure-as-code templates before provisioning, so non-compliant resources are blocked pre-deployment. This satisfies the stem's requirement to enforce compliance before deployment, shifting control left rather than detecting drift after resources already exist in the cloud environment.

  • ✗

    Conduct manual security reviews after each deployment.

    Why it's wrong here

    Manual post-deployment reviews detect violations only after resources exist, so non-compliant infrastructure is already provisioned and running. Reviews are tempting because they suit low-change environments or audit sign-off, but a CI/CD pipeline demands automated policy checks at build time, before deployment, to block non-compliant templates.

  • ✗

    Deploy resources and then scan for compliance after deployment.

    Why it's wrong here

    Post-deployment scanning detects violations only after non-compliant resources exist in the environment, so the pipeline cannot block their creation. It suits continuous monitoring of already-running workloads, where drift detection and remediation are the goal. Here, policy enforcement must occur pre-deployment, gating the pipeline before resources are provisioned.

About these practice questions

One of 934 original CCSP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.