Courseiva
mediumMultiple Choice

CCSP Practice Question: Which practice is most effective for preventing…

Which practice is most effective for preventing the deployment of container images with known vulnerabilities in a DevSecOps pipeline?

⚠ Common exam trap

The trap is choosing 'post-deployment scanning' or 'runtime monitoring' because they sound thorough — but the question asks for prevention, and only pre-push CI scanning stops vulnerable images from being deployed at all.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Image scanning in CI pipeline before push

Scanning images in the CI pipeline before they are pushed to a registry catches known vulnerabilities (CVEs) at the earliest possible stage, preventing flawed images from ever reaching production. This 'shift-left' approach blocks the build or fails the pipeline when critical vulnerabilities are found, so vulnerable images never get deployed. It is the most effective preventive control because it stops the problem at the source.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Post-deployment vulnerability scanning

    Why it's wrong here

    Post-deployment scanning detects vulnerabilities only after the image is running, so the vulnerable container has already been deployed. It is tempting because continuous scanning is genuinely required for runtime assurance and compliance reporting, but prevention demands scanning earlier, in the build or admission stage.

  • ✓

    Image scanning in CI pipeline before push

    Why this is correct

    Scanning images in CI before push catches known CVEs in base layers and dependencies while the artefact is still mutable, blocking vulnerable images from ever entering the registry. This satisfies the stem's prevention constraint, unlike runtime scanning which detects only after deployment.

  • ✗

    Using only official base images

    Why it's wrong here

    Official base images reduce inherited risk but do not guarantee that application layers or dependencies are vulnerability-free, so scanning is still required. It is tempting because trusted registries and vendor-maintained bases are sound supply-chain hygiene, yet they cannot detect flaws introduced during your own build.

  • ✗

    Runtime monitoring with a WAF

    Why it's wrong here

    A WAF inspects HTTP traffic at runtime and cannot identify vulnerable packages inside an image, so deployment already occurred. It is tempting because runtime monitoring with a WAF is correct for protecting exposed web applications against exploitation attempts, not for blocking images containing known vulnerable components.

About these practice questions

One of 934 original CCSP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.