Courseiva
Supply Chain Security →easyMultiple Choice

CKS Supply Chain Security Practice Question

A developer is building a container image and wants to ensure that the image is free from known vulnerabilities before pushing it to a registry. The developer decides to use Trivy. Which command should the developer run to scan the image for vulnerabilities?

⚠ Common exam trap

The trap here is mixing up Trivy subcommands, such as using fs or config when the target is a container image rather than a directory or IaC file.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

trivy image myapp:latest

The trivy image command is designed to scan container images for vulnerabilities. It retrieves the image, analyzes its layers, and matches installed packages against vulnerability databases. The other options either target different artifact types (filesystem, configuration files) or use a non-existent subcommand, so they would not achieve the desired scan.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    trivy fs --security-checks vuln myapp:latest

    Why it's wrong here

    The trivy fs command scans a filesystem directory for vulnerabilities and misconfigurations. It expects a path to a directory, not an image reference. Using it with an image name would cause an error because it cannot interpret the image reference as a filesystem path. Thus, it is not the correct command for scanning an image.

  • ✗

    trivy config myapp:latest

    Why it's wrong here

    The trivy config command scans infrastructure-as-code files, such as Dockerfiles, Kubernetes manifests, and Terraform configurations, for misconfigurations. It does not scan container images for vulnerabilities. Therefore, it is not suitable for the developer's goal of finding CVEs in the image.

  • ✗

    trivy repository myapp:latest

    Why it's wrong here

    Trivy does not have a repository subcommand. The available subcommands include image, fs, config, rootfs, and others. Using an invalid subcommand will result in an error. The developer should use trivy image to scan a container image for vulnerabilities.

  • ✓

    trivy image myapp:latest

    Why this is correct

    The trivy image command scans a container image for vulnerabilities. It pulls the image from the local Docker daemon or a registry, analyzes the installed packages, and reports any known CVEs. This is the standard way to use Trivy for image scanning. The command outputs a table of vulnerabilities by default.

About these practice questions

This CKS question is part of Courseiva's 845-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CNCF exam blueprint

This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.