CKS Supply Chain Security Practice Question
A DevOps team wants to enforce that all Deployments must have a specific label 'app.kubernetes.io/name'. Which tool can be used to validate this in the admission controller stage?
⚠ Common exam trap
This exam often tests the distinction between tools that operate on container images (Trivy, Cosign, Syft) versus tools that enforce policies on Kubernetes resources at admission time (Kyverno, OPA/Gatekeeper), leading candidates to confuse image scanning with admission control.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Kyverno
Kyverno is a Kubernetes-native policy engine that can validate, mutate, and generate resources using admission webhooks. It can enforce that all Deployments carry the label 'app.kubernetes.io/name' by defining a 'validate' rule in a ClusterPolicy, which checks the resource during the admission controller stage before it is persisted to etcd.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Trivy
Why it's wrong here
Trivy scans images, filesystems and IaC for vulnerabilities and misconfiguration; it does not act as an admission controller validating Deployment labels. It tempts because Trivy can scan Kubernetes manifests, which is correct for detecting insecure configuration before deployment, not enforcing required metadata.
- ✗
Cosign
Why it's wrong here
Cosign signs and verifies container image signatures against OCI registries; it never inspects Deployment manifests for labels. It tempts because Cosign does operate at admission time via policy controllers, which is correct when the requirement is verifying image provenance rather than manifest metadata.
- ✓
Kyverno
Why this is correct
Kyverno is a Kubernetes-native admission controller that validates resources against policies written as YAML, so a rule can require the app.kubernetes.io/name label on Deployments and reject non-compliant manifests at admission time, satisfying the stem's enforcement requirement.
- ✗
Syft
Why it's wrong here
Syft generates a software bill of materials by scanning images or filesystems for packages; it does not evaluate Kubernetes manifests or enforce labels. It tempts because Syft feeds supply-chain admission policies, which would be correct when the requirement is blocking images containing vulnerable components.
Go deeper
Related to this question
Learn chapter
Microservice Vulnerabilities: Secure Deployments and Runtime
Key term
Admission Controllers
Admission controllers are plugins that intercept and process requests to the Kubernetes API server after authentication and authorization, but before the request is persisted, allowing policies to be enforced on objects being created, modified, or deleted.
Key term
Node Restriction
A Kubernetes admission controller that limits what a kubelet can modify on its own node to prevent privilege escalation and unauthorized access.
About these practice questions
One of 845 original CKS practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.