CKS Supply Chain Security Practice Question
A CI/CD pipeline uses cosign attest to add an SBOM attestation to an image. Later, during deployment, which command verifies the attestation?
⚠ Common exam trap
The CKS exam often tests the distinction between `cosign verify` (for image signatures) and `cosign verify-attestation` (for attestations), and the trap here is that candidates mistakenly choose `cosign verify` thinking it covers all signed artifacts, but it does not handle the in-toto attestation envelope.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
cosign verify-attestation --key cosign.pub myimage:latest
`cosign verify-attestation` is the specific command designed to verify an in-toto attestation (such as an SBOM) attached to a container image. It checks the signature on the attestation using the provided public key (`--key cosign.pub`) and validates that the attestation's payload matches the image digest, ensuring the SBOM was generated and signed by the trusted party.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
cosign verify --key cosign.pub myimage:latest
Why it's wrong here
cosign verify only checks the image's signature, which is a detached signature protecting the container manifest digest. Attestations are stored separately as in-toto statements wrapped in a DSSE envelope, so this command never inspects their content or validity. The image could be correctly signed while its SBOM attestation is missing, stale, or signed by a different key, causing this command to succeed even when the attestation is untrusted.
- ✗
cosign attest --key cosign.key --predicate sbom.json myimage:latest
Why it's wrong here
cosign attest is a write operation that creates and attaches an in-toto attestation using a predicate file, such as an SBOM, and signs it with the provided private key. It mutates the image's attestation collection in the registry, but it performs zero verification of either the image or existing attestations. Since the goal is to verify, not generate, this command is the inverse of the required action; it would never validate a public-key-signed attestation.
- ✓
cosign verify-attestation --key cosign.pub myimage:latest
Why this is correct
cosign verify-attestation is specifically designed to cryptographically verify that the image's attestations are valid and signed by the trusted public key. It decodes the DSSE envelope, checks the in-toto statement's signature, and outputs the payload only if authentication succeeds. This is the only command here that directly addresses the SBOM attestation's integrity and the signer's identity, making it the correct choice for a pipeline's verification step.
- ✗
cosign download attestation myimage:latest
Why it's wrong here
cosign download attestation merely fetches the raw attestation payloads from the registry into stdout or a file for auditing or local inspection. It performs no signature checks with the provided public key and will happily return tampered or attacker-signed attestations without any warning. Without cryptographic validation, it cannot guarantee the SBOM came from the expected pipeline stage, so it fails as a verification command.
Go deeper
Related to this question
Learn chapter
Supply Chain Security: Container Image Security
Key term
Image Signing and Verification
Image signing and verification is the process of digitally signing a container image to prove its origin and integrity, and then checking that signature before using the image to ensure it was not tampered with.
About these practice questions
This CKS question is part of Courseiva's 845-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.