CKS Supply Chain Security Practice Question
A developer is building a container image and wants to ensure that the image is free from known vulnerabilities before pushing it to a registry. The developer decides to use Trivy. Which command should the developer run to scan the image for vulnerabilities?
⚠ Common exam trap
The trap here is mixing up Trivy subcommands, such as using fs or config when the target is a container image rather than a directory or IaC file.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
trivy image myapp:latest
The trivy image command is designed to scan container images for vulnerabilities. It retrieves the image, analyzes its layers, and matches installed packages against vulnerability databases. The other options either target different artifact types (filesystem, configuration files) or use a non-existent subcommand, so they would not achieve the desired scan.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
trivy fs --security-checks vuln myapp:latest
Why it's wrong here
The trivy fs command scans a filesystem directory for vulnerabilities and misconfigurations. It expects a path to a directory, not an image reference. Using it with an image name would cause an error because it cannot interpret the image reference as a filesystem path. Thus, it is not the correct command for scanning an image.
- ✗
trivy config myapp:latest
Why it's wrong here
The trivy config command scans infrastructure-as-code files, such as Dockerfiles, Kubernetes manifests, and Terraform configurations, for misconfigurations. It does not scan container images for vulnerabilities. Therefore, it is not suitable for the developer's goal of finding CVEs in the image.
- ✗
trivy repository myapp:latest
Why it's wrong here
Trivy does not have a repository subcommand. The available subcommands include image, fs, config, rootfs, and others. Using an invalid subcommand will result in an error. The developer should use trivy image to scan a container image for vulnerabilities.
- ✓
trivy image myapp:latest
Why this is correct
The trivy image command scans a container image for vulnerabilities. It pulls the image from the local Docker daemon or a registry, analyzes the installed packages, and reports any known CVEs. This is the standard way to use Trivy for image scanning. The command outputs a table of vulnerabilities by default.
Go deeper
Related to this question
About these practice questions
This CKS question is part of Courseiva's 845-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CNCF exam blueprint
This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.