CCSP Cloud Application Security Practice Question
Which TWO measures are effective for securing container images in a cloud environment?
⚠ Common exam trap
ISC2 often tests the misconception that 'latest tags are safe because they always point to the most recent version,' but the trap is that 'latest' is a mutable tag that can silently introduce breaking changes or vulnerabilities, whereas version pinning (e.g., using a specific digest or semantic version) ensures deterministic and auditable deployments.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Sign images to ensure integrity
Option B is correct because cryptographically signing container images (e.g., with Docker Content Trust/Notary or Sigstore Cosign) lets the orchestrator verify image integrity and provenance, ensuring only trusted, untampered images are deployed. Option E is correct because scanning images for known CVEs in OS packages and application dependencies before deployment (using tools like Trivy, Clair, or Grype) catches vulnerabilities early and prevents shipping flawed images into production. Option A is wrong because a public registry without scanning exposes images to tampering and untracked vulnerabilities, undermining supply-chain security. Option C is wrong because relying on mutable 'latest' tags without version pinning prevents reproducibility and integrity verification, making it easy to deploy unexpected or compromised images. Option D is wrong because running containers as root violates least privilege and dramatically increases the impact of a container escape or compromise.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Store images in a public registry without scanning
Why it's wrong here
A public registry exposes images to unauthenticated pull and tampering, and skipping scanning leaves known vulnerabilities undetected before deployment. It is tempting because public registries offer convenient image distribution, and would suit deliberately shared open-source base images, not proprietary workloads needing controlled, verified access.
- ✓
Sign images to ensure integrity
Why this is correct
Signing container images with cryptographic hashes, verified against a trusted registry or key management system, ensures that the image has not been tampered with during transit or storage, directly satisfying the integrity constraint of the cloud environment. This mechanism prevents unauthorised modifications, such as injected malware, from being deployed in production, which is critical for maintaining a secure supply chain.
- ✗
Use latest tags without version pinning
Why it's wrong here
The latest tag is mutable, so the same reference can resolve to different image content between builds, defeating reproducibility and allowing unreviewed code to deploy. It is tempting because latest simplifies pulling the newest build, and would suit disposable development experiments, not production images requiring immutable, auditable version pinning.
- ✗
Run containers with root privileges
Why it's wrong here
Root inside a container grants privileges that ease container-escape and host compromise if the runtime is misconfigured or a kernel flaw is exploited. It is tempting because root avoids permission errors during image build, and would suit isolated local debugging, not shared or production cloud environments where least privilege is required.
- ✓
Scan images for vulnerabilities before deployment
Why this is correct
Scanning images before deployment detects known CVEs in base layers and dependencies while the image is still in the registry, blocking vulnerable artefacts from reaching production. This satisfies the stem's container image security requirement by shifting vulnerability detection left of runtime.
Go deeper
Related to this question
About these practice questions
This CCSP question is part of Courseiva's 934-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.