CKS Supply Chain Security Practice Question
A DevOps engineer is setting up a CI/CD pipeline to scan container images for vulnerabilities. They want to fail the pipeline if any critical vulnerabilities are found. Which command should they use to scan the image and produce a JSON output that can be parsed?
⚠ Common exam trap
The trap is confusing `trivy fs` with `trivy image`, and confusing `--format` (which controls output format, such as JSON) with `--output` (which specifies a file path). The command must use `--format json`, not `--output json`.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
trivy image --severity CRITICAL --format json myimage:tag
`trivy image` scans a container image. Use `--severity CRITICAL` to filter only critical vulnerabilities and `--format json` to produce machine-parseable JSON output. This lets the pipeline parse the JSON and fail on critical vulnerabilities. Note: `--output` specifies an output file path, not the report format.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
trivy fs --severity CRITICAL --output json .
Why it's wrong here
The `fs` subcommand performs a filesystem scan, not a container image scan, so it only inspects the current directory's sources and dependency manifests (e.g., package-lock.json, go.sum) for known vulnerabilities. This approach misses OS-level packages and library versions installed inside the built image layers, so the pipeline would not catch critical vulnerabilities present in the actual `myimage:tag` artifact. For container image scanning, the correct target is `trivy image`.
- ✓
trivy image --severity CRITICAL --format json myimage:tag
Why this is correct
This is the correct command because it targets the container image (`trivy image`), restricts results to only critical-severity vulnerabilities with `--severity CRITICAL`, and outputs machine-readable JSON via `--output json`. The JSON format is ideally suited for CI/CD automation, allowing the pipeline to parse vulnerability data programmatically (e.g., with jq) and enforce policy based on exact vulnerability IDs. It directly matches the requirement to scan the built image and flag critical issues.
- ✗
trivy image --format table myimage:tag
Why it's wrong here
The `--format table` flag produces a human-readable ASCII table, which is fine for console output but difficult to parse reliably in automated CI/CD scripts because of variable column widths and alignment. It also does not restrict severity, so the output will include low, medium, high, and critical vulnerabilities, burying the critical findings in noise. For automation, JSON (or SARIF) is the required machine-parseable format, often combined with `--severity CRITICAL` to reduce output size.
- ✗
trivy image --severity HIGH myimage:tag
Why it's wrong here
The `--severity HIGH` flag filters the results to include only HIGH-severity vulnerabilities, explicitly excluding CRITICAL vulnerabilities, which are exactly the ones the pipeline is supposed to catch. Even if some critical vulnerabilities might be considered higher than high, Trivy's severity filter is strict — specifying HIGH limits output to HIGH only, so critical issues are not scanned for. Additionally, the default output format is a table, which is not machine-readable for CI/CD, although the primary failure is the incorrect severity scope.
Go deeper
Related to this question
About these practice questions
This CKS question is part of Courseiva's 845-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.