ISC2 Certified Cloud Security Professional (CCSP) Practice Question
Your organization is building a microservice that will run in a Kubernetes cluster and intends to use a popular open-source reverse-proxy image pulled from a public registry. To satisfy the company policy that mandates deployment of only validated open-source software, which action best demonstrates that the image has been properly validated before it is promoted to the production registry?
Deploy the image in an isolated namespace first and rely on runtime behavioral monitoring to spot suspicious activity.
Fork the image's source code into an internal Git repository and disable automatic updates so the code base remains unchanged.
Scan the container image with an SCA tool to create an SBOM and address any reported CVEs before copying it into the enterprise registry.
Pull the image only from its official repository on Docker Hub, trusting that the maintainers keep it secure and up to date.
Validating open-source software goes beyond simply trusting the origin or isolating the runtime. The security team needs verifiable evidence that the exact bits being deployed are known, scanned, and tracked. Generating a software bill of materials (SBOM) with a Software Composition Analysis (SCA) tool exposes all third-party components inside the image and maps them to known CVEs, enabling remediation or documented risk acceptance. Pulling from an "official" repository or forking the code without scanning provides no assurance about hidden vulnerabilities. Relying only on runtime monitoring detects issues after deployment, not before, and does not meet the definition of pre-deployment validation.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is an SBOM?
Open an interactive chat with Bash
What is an SCA tool and what does it do?
Open an interactive chat with Bash
Why is runtime behavioral monitoring not enough for software validation?
Open an interactive chat with Bash
ISC2 Certified Cloud Security Professional (CCSP)
Cloud Application Security
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .