Courseiva
Supply Chain Security →hardMultiple Choice

CKS Supply Chain Security Practice Question

A cluster uses Kyverno to enforce that all images come from a trusted registry. A new Deployment fails with a message that the image 'docker.io/library/nginx:latest' is not allowed. What Kyverno policy rule likely caused this?

⚠ Common exam trap

Many exam-takers confuse Kyverno's 'validate' rules (which deny non-compliant resources) with 'mutate' or 'generate' rules, which do not block admission; the explicit rejection message indicates that a validate rule with a condition on the image registry denied the deployment.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

A validate rule that checks the image registry

Kyverno uses validate rules to enforce policies by checking resource attributes against defined conditions. The error message indicates that the image 'docker.io/library/nginx:latest' was rejected because it does not come from a trusted registry. A validate rule with a pattern or deny condition that inspects the image field (e.g., `spec.containers[*].image`) and restricts it to a specific registry prefix (like `trusted-registry.io/*`) would cause this rejection.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    A validate rule that checks the container's resource limits

    Why it's wrong here

    A validate rule that checks the container's resource limits is unrelated to image provenance. Kyverno validate rules can inspect fields like CPU and memory requests/limits, but those fields only govern resource allocation, not where an image was pulled from. The policy requirement is to reject images from disallowed registries, which requires inspecting the image reference, not resource constraints. Thus, this rule would not block any unauthorized image.

  • ✓

    A validate rule that checks the image registry

    Why this is correct

    A validate rule that checks the image registry is the correct enforcement mechanism in Kyverno. Such a rule can use a pattern, a deny condition, or CEL expression to inspect the image field and reject any container whose registry is not in an allowed list. When the rule evaluates to deny, Kubernetes admission control fails, and the pod or workload is not created. This directly matches the requirement to enforce that all images come from approved registries.

  • ✗

    A generate rule that creates a ConfigMap

    Why it's wrong here

    A generate rule creates resources like ConfigMaps from policy data, but it does not validate or block incoming API requests. The scenario requires an admission control rule that rejects deployments with disallowed image registries, which generate rules cannot enforce. This option tempts because generate rules automate resource creation, but they lack the deny or validate logic needed for admission enforcement.

  • ✗

    A mutating rule that adds a label to the pod

    Why it's wrong here

    A mutating rule that adds a label to the pod modifies incoming resources but never denies them. Kyverno mutating rules generate JSON patches that are applied before admission, and the request proceeds to validation and persists regardless of the label's value. Adding a label does not change or inspect the container image registry, so unauthorized images would still be admitted. Mutation alone cannot enforce an admission-control policy that requires denial of disallowed images.

About these practice questions

Courseiva writes every CKS question from scratch — 845 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.