CompTIA SecurityX (CAS-005)Security EngineeringHard

A security architect is evaluating a new cloud-native application for deployment. The application uses serverless functions and containers, and processes sensitive customer data. The architect must ensure that the application's runtime environment is hardened against supply chain attacks and unauthorized code execution, specifically by ensuring that only approved, signed container images can be deployed and executed. Which security control would BEST enforce this policy?

  1. ARuntime Application Self-Protection (RASP)
  2. BContainer image scanning in the CI/CD pipeline
  3. CNetwork segmentation with micro-perimeters
  4. DContent Trust and Image Signing
Show answer & explanation

Correct answer: D. Content Trust and Image Signing

Content Trust and Image Signing (e.g., using Notary, Cosign) directly address the requirement to ensure that 'only approved, signed container images can be deployed and executed'. By cryptographically signing container images and enforcing verification at deployment time, the system can guarantee the authenticity and integrity of the images, preventing the deployment of tampered or unauthorized images, which is a critical defense against supply chain attacks and unauthorized code execution in a containerized environment.

Why the other options are wrong

  • A. RASP protects the application at runtime from attacks but doesn't prevent the deployment of an unauthorized or compromised container image in the first place.
  • B. Container image scanning in the CI/CD pipeline identifies vulnerabilities or malicious components *before* deployment, but it doesn't cryptographically *enforce* that only approved images are *executed* in the runtime environment.
  • C. Network segmentation with micro-perimeters controls network access between components but doesn't verify the integrity or authenticity of the deployed container images themselves.

Container Image Signing

Container image signing is the process of cryptographically signing a container image to verify its origin and integrity, ensuring that it has not been tampered with since it was built and published by a trusted source.

  • Crucial for supply chain security in containerized environments.
  • Uses digital signatures to verify image authenticity and integrity.
  • Enforced at deployment time by container runtime or orchestrator.
  • Prevents deployment of unauthorized or compromised images.

Memory trick: Signed Images Stop Supply Chain Compromises

More Security Engineering questions