Courseiva
Cloud Application Security →mediumMultiple Select

CCSP Cloud Application Security Practice Question

Which TWO measures are effective for securing container images in a cloud environment?

⚠ Common exam trap

ISC2 often tests the misconception that 'latest tags are safe because they always point to the most recent version,' but the trap is that 'latest' is a mutable tag that can silently introduce breaking changes or vulnerabilities, whereas version pinning (e.g., using a specific digest or semantic version) ensures deterministic and auditable deployments.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Sign images to ensure integrity

Option B is correct because cryptographically signing container images (e.g., with Docker Content Trust/Notary or Sigstore Cosign) lets the orchestrator verify image integrity and provenance, ensuring only trusted, untampered images are deployed. Option E is correct because scanning images for known CVEs in OS packages and application dependencies before deployment (using tools like Trivy, Clair, or Grype) catches vulnerabilities early and prevents shipping flawed images into production. Option A is wrong because a public registry without scanning exposes images to tampering and untracked vulnerabilities, undermining supply-chain security. Option C is wrong because relying on mutable 'latest' tags without version pinning prevents reproducibility and integrity verification, making it easy to deploy unexpected or compromised images. Option D is wrong because running containers as root violates least privilege and dramatically increases the impact of a container escape or compromise.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Store images in a public registry without scanning

    Why it's wrong here

    A public registry exposes images to unauthenticated pull and tampering, and skipping scanning leaves known vulnerabilities undetected before deployment. It is tempting because public registries offer convenient image distribution, and would suit deliberately shared open-source base images, not proprietary workloads needing controlled, verified access.

  • ✓

    Sign images to ensure integrity

    Why this is correct

    Signing container images with cryptographic hashes, verified against a trusted registry or key management system, ensures that the image has not been tampered with during transit or storage, directly satisfying the integrity constraint of the cloud environment. This mechanism prevents unauthorised modifications, such as injected malware, from being deployed in production, which is critical for maintaining a secure supply chain.

  • ✗

    Use latest tags without version pinning

    Why it's wrong here

    The latest tag is mutable, so the same reference can resolve to different image content between builds, defeating reproducibility and allowing unreviewed code to deploy. It is tempting because latest simplifies pulling the newest build, and would suit disposable development experiments, not production images requiring immutable, auditable version pinning.

  • ✗

    Run containers with root privileges

    Why it's wrong here

    Root inside a container grants privileges that ease container-escape and host compromise if the runtime is misconfigured or a kernel flaw is exploited. It is tempting because root avoids permission errors during image build, and would suit isolated local debugging, not shared or production cloud environments where least privilege is required.

  • ✓

    Scan images for vulnerabilities before deployment

    Why this is correct

    Scanning images before deployment detects known CVEs in base layers and dependencies while the image is still in the registry, blocking vulnerable artefacts from reaching production. This satisfies the stem's container image security requirement by shifting vulnerability detection left of runtime.

About these practice questions

This CCSP question is part of Courseiva's 934-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.