CKS Supply Chain Security Practice Question
A developer wants to sign a container image using Cosign. Which command should they run after building and pushing the image to a registry?
⚠ Common exam trap
The CKS exam often tests the distinction between signing (`cosign sign`) and verification (`cosign verify`), trapping candidates who confuse the action of creating a signature with the action of checking one.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
cosign sign myrepo/myapp:latest
The `cosign sign` command is used to sign a container image and attach the signature to the image in the registry. After building and pushing the image, running `cosign sign myrepo/myapp:latest` generates a digital signature using a private key and stores it as an OCI artifact (e.g., `sha256-...sig`) in the same registry, enabling later verification of the image's integrity and origin.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
cosign sign myrepo/myapp:latest
Why this is correct
Cosign stores signatures as OCI artefacts in the same registry as the image, so signing requires only the image reference. Running cosign sign against myrepo/myapp:latest generates a keyless or key-based signature attached to that digest, satisfying the post-push signing requirement.
- ✗
cosign verify myrepo/myapp:latest
Why it's wrong here
Verification checks an existing signature against a public key or keyless identity; it does not create one. It is tempting because verify and sign both operate on the same image reference, but verification is the post-signing validation step, used when confirming provenance before deployment rather than producing the signature.
- ✗
cosign attest myrepo/myapp:latest
Why it's wrong here
Attestation attaches signed metadata such as SBOMs or vulnerability scan results to an image; it does not produce the image signature itself. It is tempting because attest also uses Cosign keys and writes to the registry, but it is the correct choice only when binding predicate evidence, not signing the image.
- ✗
cosign generate-key-pair
Why it's wrong here
generate-key-pair only creates the signing keypair; after pushing, the image is signed with cosign sign, referencing the digest. It tempts because key generation is a prerequisite step, but running it after the push leaves the image unsigned, so verification would fail.
Go deeper
Related to this question
Learn chapter
Supply Chain Security: Container Image Security
Key term
Image Signing and Verification
Image signing and verification is the process of digitally signing a container image to prove its origin and integrity, and then checking that signature before using the image to ensure it was not tampered with.
About these practice questions
One of 845 original CKS practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.