AZ-400 Practice Question: Design and implement build and release pipelines
Which TWO practices help improve the security of container images in a CI/CD pipeline? (Choose two.)
⚠ Common exam trap
Candidates often confuse the 'latest' tag with a security best practice, but it undermines reproducibility and security by introducing uncontrolled updates. Also, some may think running with root privileges avoids permission issues, but it increases attack surface. Signing and scanning are the verifiable security controls.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Sign container images to verify their integrity.
Option C is correct because signing container images (e.g., with Docker Content Trust/Notary or Sigstore Cosign) creates a cryptographic signature that lets the pipeline and runtime verify image integrity and provenance, preventing tampered or spoofed images from being deployed. Option E is correct because integrating an image vulnerability scanner (such as Trivy, Clair, or Grype) into the build stage detects known CVEs in OS packages and dependencies early, allowing the pipeline to fail or block promotion of vulnerable images. Option A is wrong because running containers as root increases the attack surface and violates least-privilege; non-root users or user namespaces should be used instead. Option B is wrong because public registries expose images to unauthorized pulls and tampering; private, access-controlled registries are preferred. Option D is wrong because the mutable 'latest' tag is non-deterministic and can silently pull unvetted or breaking changes; pinned, immutable tags or digests should be used.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Run containers with root privileges to avoid permission issues.
Why it's wrong here
Running containers as root grants unnecessary privileges, expanding the attack surface and potentially allowing an attacker who compromises the container to access the host and other containers. Follow the principle of least privilege by using non-root users, read-only filesystems, and dropping capabilities.
- ✗
Store container images in a public registry for easy access.
Why it's wrong here
Public registries expose images to the world, increasing the risk of unauthorized access, tampering, or accidental exposure of sensitive data. Use private registries with access controls, authentication, and image scanning to maintain security and control over image distribution.
- ✓
Sign container images to verify their integrity.
Why this is correct
Signing images with a trusted key produces a cryptographic digest that the pipeline and runtime verify before deployment. This detects tampering or substitution between build and deploy, satisfying the integrity requirement rather than merely detecting known vulnerabilities.
- ✗
Use the 'latest' tag for base images to always get the newest patches.
Why it's wrong here
The 'latest' tag is mutable, so builds pull unpredictable image versions and cannot reproduce or pin a known-good digest. Floating tags suit development experimentation; secure pipelines pin base images by digest or immutable version tag and scan them, ensuring patched, auditable layers.
- ✓
Scan container images for vulnerabilities during the build.
Why this is correct
Scanning during the build inspects image layers against vulnerability databases, failing the pipeline before a flawed artefact reaches a registry. This shifts detection left, satisfying the requirement to catch known CVEs in base images and dependencies early.
Go deeper
Related to this question
Learn chapter
Implementing a Build Pipeline
Key term
Pipeline
A pipeline is an automated series of steps that takes code from development to production, ensuring quality and speed.
Key term
Stage
A stage is a discrete phase in a software development or deployment pipeline where code is built, tested, integrated, or released in a controlled environment.
About these practice questions
One of 696 original AZ-400 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-400 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-400 exam.