Courseiva
Supply Chain Security →hardMultiple Choice

CKS Supply Chain Security Practice Question

A Kubernetes cluster enforces image signature verification using the Cosign admission controller. A developer attempts to deploy a pod using an image that was signed with a key that is not in the trusted public key list. The pod is rejected. Which component is responsible for this rejection?

⚠ Common exam trap

The trap here is assuming that image signature verification happens at the node level via the container runtime, when in fact it is typically enforced at admission time.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The Kubernetes API server's admission chain, specifically the Cosign admission webhook.

Admission controllers in the Kubernetes API server enforce policies before objects are persisted. The Cosign admission webhook validates image signatures against a configured list of trusted public keys. If the signature does not match a trusted key, the webhook denies the pod creation, preventing unsigned or untrusted images from running.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    The Kubernetes API server's admission chain, specifically the Cosign admission webhook.

    Why this is correct

    Admission webhooks intercept API requests before persistence. The Cosign admission controller is a validating webhook that checks image signatures against trusted keys. If the signature is not valid or the key is untrusted, it rejects the pod creation request. This is the component that enforces the policy at admission time.

  • ✗

    The Kubernetes scheduler, which filters nodes based on image signature policies.

    Why it's wrong here

    The scheduler assigns pods to nodes based on resource requirements and constraints, but it does not evaluate image signatures. Signature verification is a security policy enforced by admission controllers, not the scheduler. Thus, the scheduler is not responsible for the rejection.

  • ✗

    The container runtime interface (CRI) on the node, such as containerd or CRI-O.

    Why it's wrong here

    The CRI is responsible for image management and container execution but does not inherently verify signatures unless configured with a policy tool. While some runtimes support signature verification via plugins, the scenario describes an admission controller rejection, which happens at the API server level, not the runtime.

  • ✗

    The kubelet on the node where the pod is scheduled.

    Why it's wrong here

    The kubelet is responsible for pulling images and running containers, but it does not perform signature verification by default. It relies on the container runtime and admission control for security policies. In this case, the rejection occurs before scheduling, so the kubelet is not involved.

About these practice questions

Courseiva writes every CKS question from scratch — 845 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CNCF exam blueprint

This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.