CKS Supply Chain Security Practice Question
A DevOps team wants to ensure that only signed images from a trusted registry are deployed in the cluster. They plan to use a webhook to intercept pod creation. Which tool is best suited for this task?
⚠ Common exam trap
Candidates often confuse Helm chart signing (which verifies chart provenance) with container image signing, leading them to select Option B, even though Helm does not verify the images inside the chart at pod creation time.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Kyverno with a verifyImages rule
Kyverno is a Kubernetes-native policy engine that can enforce image signature verification via its `verifyImages` rule. It intercepts pod creation through a dynamic admission webhook, checking that container images are signed with a trusted key (e.g., using Sigstore/Cosign) before the pod is admitted. This directly meets the requirement to only allow signed images from a trusted registry.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
kubectl with --validate flag
Why it's wrong here
kubectl with --validate is incorrect because that flag performs only client-side OpenAPI schema validation of a manifest against the Kubernetes API's published schema, catching field name or type errors. It does not enforce any admission policy, image signature checks, or security constraints; it runs entirely on the client machine before the request is sent. The cluster's admission controllers run server-side after the request reaches the API server, so kubectl cannot substitute for them.
- ✗
Helm with signed charts
Why it's wrong here
Helm with signed charts is the wrong tool because Helm chart signing only cryptographically verifies the integrity and provenance of the chart package during `helm install` — it runs client-side and never touches the Kubernetes API server at pod creation time. Signed charts do not enforce which container images are allowed to run; they merely assure the chart's templates and defaults haven't been tampered with. Runtime image signature verification requires an admission controller, not a package manager.
- ✗
etcd with encryption at rest
Why it's wrong here
etcd encryption at rest is incorrect because it protects sensitive cluster data (like Secrets) while stored on disk, but it has no role in admission control or image verification. When a Pod is created, the API server reads from etcd but does not consult etcd to decide whether an image's signature is valid. Encryption at rest addresses data confidentiality, not supply-chain security for container images.
- ✓
Kyverno with a verifyImages rule
Why this is correct
Kyverno with a verifyImages rule is correct because Kyverno runs as a dynamic admission controller inside the cluster and intercepts Pod creation requests before they are persisted. The verifyImages rule leverages cosign to check each container image's digital signature against the specified public keys, failing admission if the signature is missing or invalid. This enforces a policy that only signed images from trusted registries can run, at the exact point Kubernetes decides to allow the workload.
- ✗
Prometheus with alerting rules
Why it's wrong here
Prometheus with alerting rules is wrong because Prometheus is a metrics and alerting system that scrapes time-series data after workloads are already running. It cannot inspect image signatures during the admission phase, nor can it block a Pod from being created. Alerts may notify you that an unsigned image is running, but they provide no preventive control and are not part of the Kubernetes API request path.
Go deeper
Related to this question
Learn chapter
Supply Chain Security: Container Image Security
Key term
Image Signing and Verification
Image signing and verification is the process of digitally signing a container image to prove its origin and integrity, and then checking that signature before using the image to ensure it was not tampered with.
About these practice questions
One of 845 original CKS practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.