ISC2 Certified Cloud Security Professional (CCSP) Practice Question
Your team is refactoring a monolithic payroll application into container-based microservices that will run on a managed Kubernetes service. To address the impact of containers and DevSecOps within the cloud reference architecture, which design decision MOST effectively strengthens workload isolation while enabling automated security checks during the CI/CD pipeline?
Create each microservice from a minimal base image, deploy it in its own Kubernetes namespace, and have the pipeline run an image vulnerability scan on every build before promotion.
Package all microservices into a single container image to reduce inter-pod traffic and manually sign the image only during annual release cycles.
Run containers in privileged mode with host networking enabled to simplify troubleshooting and avoid namespace overhead.
Disable Kubernetes role-based access control so the CI/CD service account can deploy freely, relying on perimeter firewalls for security.
Selecting minimal base images shrinks the software footprint inside each container, reducing the number of potential vulnerabilities. Placing every microservice in its own Kubernetes namespace provides logical segregation that limits the blast radius of a compromise. Finally, invoking an automated image-vulnerability scan on every build integrates security early and continuously, which is a core DevSecOps practice. The other options weaken security or violate DevSecOps intent: bundling all services in one image eliminates micro-segmentation and typically increases attack surface; disabling RBAC or admission controls gives excessive privileges and bypasses preventive controls; running privileged containers with host networking removes key isolation features and enlarges the attack surface.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is Kubernetes role-based access control (RBAC)?
Open an interactive chat with Bash
What is a Kubernetes namespace and how does it strengthen container isolation?
Open an interactive chat with Bash
Why are minimal base images important for container security?
Open an interactive chat with Bash
ISC2 Certified Cloud Security Professional (CCSP)
Cloud Concepts, Architecture and Design
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .