Courseiva
Supply Chain Security →hardMultiple Choice

CKS Supply Chain Security Practice Question

A security audit reveals that a Deployment uses an image with a mutable tag 'app:latest'. Which change ensures the image is immutable and traceable?

⚠ Common exam trap

A common misconception is that using a 'stable' tag provides immutability, but in Kubernetes, any tag can be reassigned. Only the image digest (SHA256) guarantees a specific image version, ensuring traceability and supply chain security.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Use 'image: app@sha256:abc123...'

Using the image digest (e.g., `image: app@sha256:abc123...`) pins the container image to an immutable, content-addressable identifier. Unlike mutable tags, the digest is a cryptographic hash of the image manifest, ensuring that every pull returns the exact same image, which is critical for traceability and supply chain security.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Change tag to 'app:stable'

    Why it's wrong here

    A tag like 'app:stable' is a mutable pointer that can be reassigned to a different image digest at any time by anyone with push access. Tag updates do not change your Deployment's spec, so the same tag may reference a vulnerable image later. Immutability requires referencing the exact content via its sha256 digest, not a human-readable label.

  • ✗

    Set 'replicas: 1'

    Why it's wrong here

    Setting replicas to 1 only limits the number of running pods; it does not lock the image that those pods use. The Deployment's image field still resolves to a tag, and if that tag is updated in the registry, a future rollout or pod restart could pull the new, possibly compromised image. Replica count has no influence on image supply chain integrity.

  • ✓

    Use 'image: app@sha256:abc123...'

    Why this is correct

    Referencing the image with 'image: app@sha256:abc123...' pins the exact immutable manifest by its cryptographic digest. Kubelet fetches that exact digest from the registry, ignoring any tag association, so even if a tag is moved or overwritten, the pods will run the originally audited content. This is the only option that guarantees the image you tested is the image that runs.

  • ✗

    Add 'imagePullPolicy: Always'

    Why it's wrong here

    Setting imagePullPolicy: Always forces the kubelet to attempt pulling the image on every container creation, but it still uses the tag specified in the image field. If a mutable tag is used, Always actually increases the chance that an updated, potentially malicious image will be pulled into your cluster. It does not provide immutability; it only prevents stale cache reuse.

About these practice questions

Courseiva writes every CKS question from scratch — 845 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on CKS

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. A security policy requires that all container images use SHA-based digests instead of tags. Which approach ensures this in a Deployment YAML?

medium
  • A.Use the 'image' field with a tag and also set 'digest' field
  • B.Set imagePullPolicy: Always and use tags
  • ✓ C.Use the image field with a digest, e.g., 'image: nginx@sha256:abc123'
  • D.Set imagePullPolicy: IfNotPresent and use tags

Why C: Kubernetes supports using a SHA-based digest in the `image` field, which ensures the exact image content is pulled regardless of tag changes. By specifying the image as `nginx@sha256:abc123`, the container runtime fetches the image by its immutable digest, guaranteeing supply chain integrity and compliance with the security policy.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.