Courseiva
Supply Chain Security →hardMultiple Choice

CKS Supply Chain Security Practice Question

A DevOps team wants to enforce that all Deployments must have a specific label 'app.kubernetes.io/name'. Which tool can be used to validate this in the admission controller stage?

⚠ Common exam trap

This exam often tests the distinction between tools that operate on container images (Trivy, Cosign, Syft) versus tools that enforce policies on Kubernetes resources at admission time (Kyverno, OPA/Gatekeeper), leading candidates to confuse image scanning with admission control.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Kyverno

Kyverno is a Kubernetes-native policy engine that can validate, mutate, and generate resources using admission webhooks. It can enforce that all Deployments carry the label 'app.kubernetes.io/name' by defining a 'validate' rule in a ClusterPolicy, which checks the resource during the admission controller stage before it is persisted to etcd.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Trivy

    Why it's wrong here

    Trivy scans images, filesystems and IaC for vulnerabilities and misconfiguration; it does not act as an admission controller validating Deployment labels. It tempts because Trivy can scan Kubernetes manifests, which is correct for detecting insecure configuration before deployment, not enforcing required metadata.

  • ✗

    Cosign

    Why it's wrong here

    Cosign signs and verifies container image signatures against OCI registries; it never inspects Deployment manifests for labels. It tempts because Cosign does operate at admission time via policy controllers, which is correct when the requirement is verifying image provenance rather than manifest metadata.

  • ✓

    Kyverno

    Why this is correct

    Kyverno is a Kubernetes-native admission controller that validates resources against policies written as YAML, so a rule can require the app.kubernetes.io/name label on Deployments and reject non-compliant manifests at admission time, satisfying the stem's enforcement requirement.

  • ✗

    Syft

    Why it's wrong here

    Syft generates a software bill of materials by scanning images or filesystems for packages; it does not evaluate Kubernetes manifests or enforce labels. It tempts because Syft feeds supply-chain admission policies, which would be correct when the requirement is blocking images containing vulnerable components.

Go deeper

Related to this question

About these practice questions

One of 845 original CKS practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.