mediumMultiple Choice
CCSP Practice Question: Which practice is most effective for preventing…
Which practice is most effective for preventing the deployment of container images with known vulnerabilities in a DevSecOps pipeline?
⚠ Common exam trap
The trap is choosing 'post-deployment scanning' or 'runtime monitoring' because they sound thorough — but the question asks for prevention, and only pre-push CI scanning stops vulnerable images from being deployed at all.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Image scanning in CI pipeline before push
Scanning images in the CI pipeline before they are pushed to a registry catches known vulnerabilities (CVEs) at the earliest possible stage, preventing flawed images from ever reaching production. This 'shift-left' approach blocks the build or fails the pipeline when critical vulnerabilities are found, so vulnerable images never get deployed. It is the most effective preventive control because it stops the problem at the source.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Post-deployment vulnerability scanning
Why it's wrong here
Post-deployment scanning detects vulnerabilities only after the image is running, so the vulnerable container has already been deployed. It is tempting because continuous scanning is genuinely required for runtime assurance and compliance reporting, but prevention demands scanning earlier, in the build or admission stage.
- ✓
Image scanning in CI pipeline before push
Why this is correct
Scanning images in CI before push catches known CVEs in base layers and dependencies while the artefact is still mutable, blocking vulnerable images from ever entering the registry. This satisfies the stem's prevention constraint, unlike runtime scanning which detects only after deployment.
- ✗
Using only official base images
Why it's wrong here
Official base images reduce inherited risk but do not guarantee that application layers or dependencies are vulnerability-free, so scanning is still required. It is tempting because trusted registries and vendor-maintained bases are sound supply-chain hygiene, yet they cannot detect flaws introduced during your own build.
- ✗
Runtime monitoring with a WAF
Why it's wrong here
A WAF inspects HTTP traffic at runtime and cannot identify vulnerable packages inside an image, so deployment already occurred. It is tempting because runtime monitoring with a WAF is correct for protecting exposed web applications against exploitation attempts, not for blocking images containing known vulnerable components.
Go deeper
Related to this question
About these practice questions
One of 934 original CCSP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.