Courseiva
Supply Chain Security →mediumMultiple Choice

CKS Supply Chain Security Practice Question

A CI/CD pipeline builds a Docker image and pushes it to a registry. To ensure supply chain security, the pipeline should scan the image for vulnerabilities before deployment. Which of the following is the correct command to scan a local Docker image using Trivy?

⚠ Common exam trap

The CKAD/CKS exam often tests the distinction between Trivy subcommands (e.g., `image` vs. `fs` vs. `repo`) to catch candidates who assume a generic `scan` or `check` verb exists, mirroring common misconceptions from other tools like Docker Scout or Snyk.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

trivy image myimage:latest

`trivy image` is the specific subcommand used to scan a local Docker image for vulnerabilities. Trivy requires the `image` subcommand followed by the image name and tag (e.g., `myimage:latest`) to analyze the image layers and report CVEs. This command directly integrates with the local Docker daemon to access the image.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    trivy fs --image myimage:latest

    Why it's wrong here

    The `trivy fs` subcommand is for scanning an arbitrary filesystem, directory, or even a single file, not a container image. Passing `--image myimage:latest` is also an invalid flag combination because `trivy fs` expects a path argument, and it does not unpack or inspect image layers, registry metadata, or the image manifest. In a CI/CD pipeline, using this would scan the local working directory or a provided filesystem path, completely missing the packaged image contents and any OS-level or application dependencies embedded in the image.

  • ✓

    trivy image myimage:latest

    Why this is correct

    This is the correct command because `trivy image` is the dedicated subcommand for scanning container images. It resolves `myimage:latest` from the local Docker daemon cache or a remote registry, analyzes the image layers and SBOM of OS packages (like Alpine, Debian, CentOS) and language-specific dependencies (pip, npm, cargo, etc.), and then compares them against the Trivy vulnerability database to report CVEs. In a CI/CD pipeline, running this after `docker build` but before `docker push` catches vulnerable images before they are published.

  • ✗

    trivy scan myimage:latest

    Why it's wrong here

    The subcommand `trivy scan` does not exist in the Trivy CLI; Trivy's architecture uses action-oriented subcommands such as `image`, `fs`, `repo`, `config`, and `sbom` to select the scan target. Running `trivy scan` would cause a CLI error about an unknown command, and even if it were accepted, it would lack the context needed to identify whether the argument is an image name, a file path, or a remote repository. The correct target-specific subcommand for a Docker image is unambiguously `image`.

  • ✗

    trivy check myimage:latest

    Why it's wrong here

    There is no `trivy check` subcommand; this is a common confusion with `trivy config` (or `trivy conf`), which scans Infrastructure-as-Code files for misconfiguration issues, not for container vulnerabilities. Even if `trivy check` existed, it would be a generic verb that doesn't specify whether to scan an image, a filesystem, or a configuration file, so the CLI would not know how to interpret `myimage:latest`. Always use the explicit `image` subcommand when the target is a container image.

About these practice questions

One of 845 original CKS practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.