CKS Supply Chain Security Practice Question
A cluster uses Kyverno to enforce that all images come from a trusted registry. A new Deployment fails with a message that the image 'docker.io/library/nginx:latest' is not allowed. What Kyverno policy rule likely caused this?
⚠ Common exam trap
Many exam-takers confuse Kyverno's 'validate' rules (which deny non-compliant resources) with 'mutate' or 'generate' rules, which do not block admission; the explicit rejection message indicates that a validate rule with a condition on the image registry denied the deployment.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
A validate rule that checks the image registry
Kyverno uses validate rules to enforce policies by checking resource attributes against defined conditions. The error message indicates that the image 'docker.io/library/nginx:latest' was rejected because it does not come from a trusted registry. A validate rule with a pattern or deny condition that inspects the image field (e.g., `spec.containers[*].image`) and restricts it to a specific registry prefix (like `trusted-registry.io/*`) would cause this rejection.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
A validate rule that checks the container's resource limits
Why it's wrong here
A validate rule that checks the container's resource limits is unrelated to image provenance. Kyverno validate rules can inspect fields like CPU and memory requests/limits, but those fields only govern resource allocation, not where an image was pulled from. The policy requirement is to reject images from disallowed registries, which requires inspecting the image reference, not resource constraints. Thus, this rule would not block any unauthorized image.
- ✓
A validate rule that checks the image registry
Why this is correct
A validate rule that checks the image registry is the correct enforcement mechanism in Kyverno. Such a rule can use a pattern, a deny condition, or CEL expression to inspect the image field and reject any container whose registry is not in an allowed list. When the rule evaluates to deny, Kubernetes admission control fails, and the pod or workload is not created. This directly matches the requirement to enforce that all images come from approved registries.
- ✗
A generate rule that creates a ConfigMap
Why it's wrong here
A generate rule creates resources like ConfigMaps from policy data, but it does not validate or block incoming API requests. The scenario requires an admission control rule that rejects deployments with disallowed image registries, which generate rules cannot enforce. This option tempts because generate rules automate resource creation, but they lack the deny or validate logic needed for admission enforcement.
- ✗
A mutating rule that adds a label to the pod
Why it's wrong here
A mutating rule that adds a label to the pod modifies incoming resources but never denies them. Kyverno mutating rules generate JSON patches that are applied before admission, and the request proceeds to validation and persists regardless of the label's value. Adding a label does not change or inspect the container image registry, so unauthorized images would still be admitted. Mutation alone cannot enforce an admission-control policy that requires denial of disallowed images.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CKS question from scratch — 845 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.