CKS Supply Chain Security Practice Question
A security admin wants to ensure that only images signed with a specific key can run in the cluster. Which admission controller should be enabled?
⚠ Common exam trap
The distinction between generic webhook controllers (MutatingAdmissionWebhook and ValidatingAdmissionWebhook) and the purpose-built ImagePolicyWebhook is a common point of confusion. Candidates often mistakenly choose a generic webhook when the question explicitly asks for the admission controller designed for image signature enforcement.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
ImagePolicyWebhook
The ImagePolicyWebhook admission controller allows a cluster to enforce that only container images signed with a specific key can run. It intercepts pod creation requests and queries an external webhook to verify the image signature before admitting the pod. This directly meets the requirement of restricting execution to signed images.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
PodSecurityPolicy
Why it's wrong here
PodSecurityPolicy is a deprecated admission controller that enforced security contexts on pods, such as user IDs, SELinux labels, and privilege escalation. It has no mechanism for verifying container image provenance or cryptographic signatures. Even before its removal in Kubernetes 1.25, it never interacted with image registries or signature stores, so it cannot ensure that only signed images are admitted to the cluster.
- ✗
MutatingAdmissionWebhook
Why it's wrong here
A MutatingAdmissionWebhook can intercept and modify pod specifications before they are persisted, but it is a general-purpose extension point for altering resources, not a purpose-built image verification mechanism. To enforce signed images via this hook, you would need to build custom logic that validates signatures and then rejects the pod, effectively re-implementing the ImagePolicyWebhook behavior. Kubernetes provides the dedicated ImagePolicyWebhook specifically because signature validation is a distinct policy concern that benefits from a standard, pluggable interface rather than a generic mutating hook.
- ✓
ImagePolicyWebhook
Why this is correct
ImagePolicyWebhook is the correct choice because it is a specialized admission controller that delegates image policy decisions to an external webhook service. The kubelet sends the image name, pull spec, and associated metadata to the configured webhook, which can then validate cryptographic signatures or enforce a deny-list/allow-list before the image is used. This design is the native Kubernetes mechanism for ensuring that only signed or pre-approved images enter the cluster, and it operates at the point of image resolution rather than at pod creation.
- ✗
ValidatingAdmissionWebhook
Why it's wrong here
A ValidatingAdmissionWebhook can reject requests based on arbitrary validation logic, and in theory it could inspect and verify image signatures, but that is not its intended or dedicated purpose. The core difference is that ImagePolicyWebhook is the first-class admission controller designed specifically for image policy and signature validation, with a defined request/response schema that integrates with kubelet's image pull decisions. Using a ValidatingAdmissionWebhook for this would require building custom signature-checking logic and would not leverage the built-in image policy features, making it a less direct and more error-prone approach.
Go deeper
Related to this question
Learn chapter
Cluster Hardening: Resource Quotas and Limit Ranges
Key term
Node Restriction
A Kubernetes admission controller that limits what a kubelet can modify on its own node to prevent privilege escalation and unauthorized access.
Key term
OPA Gatekeeper
OPA Gatekeeper is a Kubernetes admission controller that enforces custom security and compliance policies on resources before they are created or updated in a cluster.
About these practice questions
This CKS question is part of Courseiva's 845-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on CKS
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. A security admin runs 'trivy image --severity CRITICAL,HIGH myrepo/myapp:latest' and sees many CVEs. The admin wants to ensure that only images with no CRITICAL or HIGH severity vulnerabilities are deployed to the cluster. Which admission controller should be configured to enforce this policy?
medium- A.PodSecurityPolicy
- B.ValidatingAdmissionWebhook
- C.MutatingAdmissionWebhook
- ✓ D.ImagePolicyWebhook
Why D: The ImagePolicyWebhook admission controller is specifically designed to evaluate container images against an external policy backend before they are admitted into the cluster. By configuring it to reject images with CRITICAL or HIGH severity vulnerabilities (as reported by Trivy), the admin can enforce that only compliant images are deployed. This controller intercepts Pod creation requests and queries an external webhook to decide whether to allow or deny the image based on the policy.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.