CKS Supply Chain Security Practice Question
A security admin wants to ensure that all container images in a Kubernetes cluster are scanned for known vulnerabilities before being deployed. Which tool can be integrated into a CI/CD pipeline to scan container images for CVEs?
⚠ Common exam trap
A common mix-up: candidates confuse static analysis tools for Kubernetes manifests (like kubesec) with container image vulnerability scanners, or assume that Helm or kubectl have built-in scanning capabilities, when in fact they do not.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Trivy
Trivy is a comprehensive vulnerability scanner for container images, filesystems, and Git repositories. It can be integrated into CI/CD pipelines to automatically scan container images for known CVEs before deployment, making it the correct choice for this requirement.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
kubesec
Why it's wrong here
kubesec analyses Kubernetes YAML manifests for security misconfigurations such as privileged containers; it does not inspect image layers for CVEs. It is tempting because it is a Kubernetes security scanner, which would be correct for validating pod specs before admission rather than scanning images.
- ✓
Trivy
Why this is correct
Trivy scans container image layers and installed OS packages against vulnerability databases, reporting CVEs before deployment. Integrating it into the CI/CD pipeline satisfies the stem's requirement to detect known vulnerabilities pre-deployment, unlike admission controllers or runtime tools that act only after images reach the cluster.
- ✗
Helm
Why it's wrong here
Helm packages and deploys Kubernetes manifests; it performs no image vulnerability scanning. It is tempting because it sits in the CI/CD delivery path, which would be correct for templating and releasing applications, not for detecting CVEs in container images.
- ✗
kubectl
Why it's wrong here
kubectl is the Kubernetes API client for managing cluster objects such as pods and deployments; it contains no vulnerability scanner or CVE database. It is tempting because it is the primary tool admins use daily, but image scanning requires a dedicated scanner like Trivy or Clair invoked in the pipeline.
Go deeper
Related to this question
About these practice questions
This CKS question is part of Courseiva's 845-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.