Courseiva
Supply Chain Security →easyMultiple Choice

CKS Supply Chain Security Practice Question

A developer runs 'trivy image myapp:latest' and gets a report with several CRITICAL CVEs. Which action would BEST address the supply chain security risk?

⚠ Common exam trap

This exam often tests the misconception that security controls like sandboxing or network policies are sufficient to fix vulnerabilities, when in fact supply chain security requires eliminating the vulnerable components at the image build stage.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Rebuild the image using a minimal base image like distroless or alpine with no CVEs

Rebuilding the image using a minimal base image like distroless or Alpine directly eliminates the vulnerable packages that cause the CRITICAL CVEs. This addresses the root cause of the supply chain risk by ensuring the container image contains only the necessary runtime dependencies, reducing the attack surface and removing known vulnerabilities at the source.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Ignore the report because the container is running in a sandboxed environment

    Why it's wrong here

    Ignoring the report because the container runs in a sandboxed environment is misguided because sandboxing technologies like gVisor or seccomp only constrain runtime behavior; they do not patch the vulnerable code present in the image layers. A known CVE in a library can still be exploited if the sandbox is misconfigured, has a bypass, or if the vulnerability is reachable via a syscall allowed by the sandbox. Moreover, the same image might be deployed later in a less isolated environment, making the vulnerability exploitable then. Therefore, this approach is unsafe and leaves the attack surface intact.

  • ✗

    Run 'trivy image myapp:latest --severity CRITICAL' to filter out lower severity findings

    Why it's wrong here

    Running trivy with --severity CRITICAL merely filters the output to show only critical findings, hiding lower-severity CVEs that could still be part of an attack chain or escalate privileges. It does not alter the image content or patch any packages, so the vulnerabilities remain present and exploitable in the running container. This creates a false sense of security and violates best practices for vulnerability management, which require remediation of all known issues, not just selective reporting.

  • ✓

    Rebuild the image using a minimal base image like distroless or alpine with no CVEs

    Why this is correct

    Rebuilding the image with a minimal base image such as distroless or a slim alpine variant is the correct remediation because these bases contain only the runtime dependencies needed for the application, eliminating the package manager, shell, and other tools that often carry CVEs. By reducing the number of installed packages, the attack surface is significantly minimized, and many reported vulnerabilities are directly removed from the image. This approach addresses the root cause of the vulnerabilities rather than masking them, and aligns with the security principle of least privilege applied to container images.

  • ✗

    Add a network policy to block outbound traffic from the container

    Why it's wrong here

    Adding a network policy to block outbound traffic is a runtime security control that can limit data exfiltration or lateral movement, but it does nothing to remove or mitigate the CVEs present in the image layers. An attacker who exploits a vulnerable service inside the container could still execute code, access sensitive files, or use local resources; the network policy only blocks certain network connections, not the vulnerability itself. This measure should be part of a layered defense but cannot be solely relied upon to fix the reported image vulnerabilities.

About these practice questions

One of 845 original CKS practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.