Courseiva
Supply Chain Security →mediumMultiple Choice

CKS Supply Chain Security Practice Question

A Kubernetes cluster has Kyverno installed. A policy requires that all images come from a trusted registry 'trusted.example.com'. A Deployment uses the image 'nginx:latest'. When the Deployment is created, it is blocked. What Kyverno policy action is being used?

⚠ Common exam trap

It's easy for candidates to confuse `audit` mode (which reports violations but allows creation) with `enforce` mode (which blocks creation), or they mistakenly think `mutate` can block resources when it only modifies them after admission.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

validate with failureAction: enforce

Kyverno's `validate` policy with `failureAction: enforce` is the mechanism that blocks resource creation when validation rules are violated. In this scenario, the policy checks that the image comes from `trusted.example.com`, and since `nginx:latest` does not match, the policy actively denies the Deployment, which is the behavior of `enforce` mode.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    validate with failureAction: enforce

    Why this is correct

    A validate policy with failureAction: enforce configures Kyverno to actively reject any resource that does not match the required pattern. When the validation rule fails, the admission webhook returns a denial to the API server, preventing the resource from being created or updated. This is the correct way to make a 'require' policy block non-compliant resources.

  • ✗

    audit

    Why it's wrong here

    A validate policy with failureAction: audit still evaluates the resource but does not block it; it records the violation in a policy report and may emit a warning, allowing the non-compliant resource to be created anyway. Because the goal is to force compliance, audit mode is insufficient because it only provides visibility without enforcement. This is useful for testing or reporting but not for enforcing a 'require' constraint.

  • ✗

    mutate

    Why it's wrong here

    A mutate policy is used to automatically patch incoming resources, such as adding labels or setting defaults, but it cannot deny a resource. The mutation rule rewrites the request before validation, and if the policy's 'require' condition would need a denial, mutation has no mechanism to block admission. For a requirement that a resource must already conform, checking via a validate policy is necessary rather than mutating it.

  • ✗

    generate

    Why it's wrong here

    A generate policy creates a new child resource (like a ConfigMap or Namespace) whenever a triggering resource is created or updated; it does not assess or block the triggering resource's compliance. It runs independently of the resource's content, so it cannot enforce a 'require' condition on the existing resource. Thus generate ignores whether the resource meets the requirement and fails to provide any enforcement.

About these practice questions

One of 845 original CKS practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.