CKS Supply Chain Security Practice Question
A CI pipeline fails with the error 'cosign: error: unable to verify image: no matching signatures' when running 'cosign verify --key pubkey.pem myregistry/myapp:latest'. The image was previously signed with a private key. What is the MOST likely cause?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The image tag was overwritten without signing
If the image tag was overwritten (e.g., pushed again without signing), the old signatures are lost and the new image is unsigned.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The public key is incorrect
Why it's wrong here
A mismatched or rotated public key would trigger a signature verification failure during `cosign verify` (e.g., "invalid signature" or "key mismatch"), not the observed error about being unable to locate signatures. The message indicates that no signed artifact exists for the current image digest, which is a state-of-the-image problem, not a cryptographic key problem. Even if the key were wrong, cosign would still find the signature tag and then fail to verify it, producing a distinctly different diagnostic.
- ✗
The registry requires authentication
Why it's wrong here
Registry authentication errors surface during the initial manifest fetch or token exchange, typically as `unauthorized: authentication required` or `denied: requested access to the resource is denied`. Since the pipeline reached the signature-lookup stage, cosign had already authenticated and retrieved the image manifest; otherwise it would not know the image digest. A registry permission issue that only affected `.sig` tags would return an explicit access-denied error for that tag, not a generic "unable to" absence message.
- ✗
Cosign is not installed correctly
Why it's wrong here
If cosign were missing, misconfigured, or installed incorrectly, the shell would fail with `cosign: command not found` or a dynamic library loading error, stopping before any signature logic runs. The fact that the pipeline prints a cosign-specific error about failing to retrieve or locate signatures proves the binary executed correctly. A correct installation is a prerequisite for producing this error; the root cause therefore lies not in the tooling but in the absent signature payload for the current image.
- ✓
The image tag was overwritten without signing
Why this is correct
Cosign stores the signature for an image in a separate tag derived from the image digest (e.g., `sha256-<digest>.sig`) and does not use mutable tags like `latest` for signature lookup. When a CI pipeline overwrites a tag with a newly built image, the new image digest does not yet have a corresponding signature tag, so `cosign verify` finds no signatures for that digest. The old signature is still present but only applies to the previous digest, so verification fails with a "missing signature" error until the new image is explicitly signed after the push.
Go deeper
Related to this question
Learn chapter
Supply Chain Security: Container Image Security
Key term
Image Signing and Verification
Image signing and verification is the process of digitally signing a container image to prove its origin and integrity, and then checking that signature before using the image to ensure it was not tampered with.
About these practice questions
Courseiva writes every CKS question from scratch — 845 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.