ISC2 Certified Secure Software Lifecycle Professional (CSSLP) Practice Question
Your DevOps team is preparing to containerize a new application. To satisfy corporate secure-configuration policy, every container must begin from an approved baseline security configuration. Which practice best fulfills the definition of a baseline security configuration for these containers?
Build all containers from a centrally maintained, hardened golden image stored in version control and update it only through a formal change process.
Rely on a host-based intrusion detection system inside containers to spot and block malicious activity at runtime.
Include root SSH access enabled in the base image and instruct teams to disable it manually in production stages.
Allow each developer to craft images independently, provided an automated vulnerability scan is run before release.
A baseline security configuration is a formally approved, standard set of hardened settings from which systems are built and deployed. Creating and version-controlling a single, locked-down golden image ensures every container starts from the same vetted state and that any later changes require an approved update to the baseline. Simply scanning ad hoc images, toggling insecure defaults by hand, or relying on runtime intrusion detection may improve security, but they do not establish the consistent, predefined foundation that characterizes a true baseline configuration.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
Why is a golden image used as a baseline security configuration?
Open an interactive chat with Bash
What is the significance of version control in maintaining the security of a golden image?
Open an interactive chat with Bash
How does hardening improve container security in a baseline configuration?
Open an interactive chat with Bash
ISC2 Certified Secure Software Lifecycle Professional (CSSLP)
Secure Software Implementation
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .