Courseiva
Cloud Application Security →mediumMultiple Select

CCSP Cloud Application Security Practice Question

Which TWO of the following are considered best practices for securing containerized applications in a cloud environment?

⚠ Common exam trap

ISC2 often tests the misconception that SSH or debugging tools are necessary for container management, when in fact they violate the immutable and ephemeral principles of container security; the trap is that candidates confuse traditional server administration with cloud-native container operations.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Run containers with a non-root user.

Option A is correct because running containers with a non-root user (via the USER directive in the Dockerfile or runAsNonRoot/runAsUser in a Kubernetes securityContext) enforces least privilege, so a container breakout or compromised process cannot gain root-level access to the host or mounted resources. Option E is correct because mounting the container's root filesystem as read-only (docker run --read-only or readOnlyRootFilesystem: true in Kubernetes) prevents attackers from modifying binaries, writing malware, or persisting changes, and any needed writable paths can be explicitly mounted as tmpfs or volumes. Option B is not a best practice: enabling SSH inside a container increases the attack surface, bloats the image, and contradicts the immutable, single-process container model; administration should use docker exec, kubectl exec, or orchestration APIs instead. Option C is wrong because the 'latest' tag is mutable and non-deterministic, breaking reproducibility and potentially pulling in unvetted or vulnerable base images; images should be pinned to specific immutable digests or version tags. Option D is also wrong because bundling debugging tools enlarges the attack surface and image size; troubleshooting should be done with ephemeral debug containers or sidecars rather than shipping tools in production images.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Run containers with a non-root user.

    Why this is correct

    Running containers as a non-root user removes the default root privileges inside the container namespace, so a compromised process cannot escalate to host-level actions or write to protected paths. This directly reduces the blast radius of container breakout, satisfying the best-practice requirement for securing containerised cloud workloads.

  • ✗

    Enable SSH inside the container for remote administration.

    Why it's wrong here

    SSH inside a container adds an interactive daemon and credentials, enlarging the attack surface and bypassing orchestration logging; containers should be immutable and administered via the orchestrator's API or ephemeral debug pods. It tempts because SSH is familiar for troubleshooting long-lived virtual machines, where persistent remote shells are the norm.

  • ✗

    Use the 'latest' tag for base images to get the newest features.

    Why it's wrong here

    The 'latest' tag is mutable, so builds become non-reproducible and a compromised or breaking upstream image can be pulled silently; pinning immutable digests or version tags is required. It tempts because 'latest' appears to guarantee current patches, which suits disposable local development images rather than production supply chains.

  • ✗

    Include debugging tools inside the container for troubleshooting.

    Why it's wrong here

    Debugging utilities (shells, network tools) enlarge the attack surface and can be leveraged post-compromise for lateral movement; production images should be minimal, with debugging done via ephemeral sidecars or copies. It tempts because baked-in tools speed up interactive troubleshooting, which is acceptable for local development images, not hardened runtime artefacts.

  • ✓

    Use a read-only filesystem for the container.

    Why this is correct

    Mounting the container filesystem read-only prevents an attacker or compromised process from writing malware, altering binaries, or persisting across restarts. Immutable runtime storage therefore limits post-exploitation tampering, satisfying the best-practice requirement for hardening containerised applications in the cloud.

About these practice questions

Courseiva writes every CCSP question from scratch — 934 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.