CKS Supply Chain Security Practice Question
A security engineer is configuring a Kubernetes cluster to enforce that all container images are signed by a trusted key before deployment. They deploy the Cosign admission controller and configure it with a public key. However, they notice that some pods are still being admitted with unsigned images. What is the most likely cause?
⚠ Common exam trap
The trap here is overlooking the scope of admission webhooks, assuming that deploying the webhook automatically enforces the policy everywhere without checking selectors.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The admission controller's namespaceSelector or objectSelector excludes the namespaces where these pods are being created.
Admission webhooks can be selectively applied based on namespace or object labels. If the namespaceSelector in the webhook configuration does not match the namespaces where pods are created, the webhook is bypassed. This allows unsigned images to be admitted. Checking the webhook's scope is essential to ensure it applies cluster-wide or to all relevant namespaces.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The Cosign admission controller is configured with a failure policy of Ignore, so if the webhook is unavailable, pods are admitted.
Why it's wrong here
A failure policy of Ignore would allow pods if the webhook call fails, but the scenario states that unsigned images are being admitted, implying the webhook is reachable but not enforcing. This policy would only matter during webhook downtime, not for normal operation. Thus, it is not the most likely cause of consistent admissions of unsigned images.
- ✗
The container runtime is configured to skip signature verification for images from certain registries.
Why it's wrong here
The container runtime does not perform signature verification by default; that is the role of the admission controller. Even if the runtime had such a configuration, it would not affect admission control. Therefore, this is not a plausible cause for unsigned images being admitted.
- ✓
The admission controller's namespaceSelector or objectSelector excludes the namespaces where these pods are being created.
Why this is correct
Admission webhooks can be scoped using namespaceSelector or objectSelector. If the namespaces where unsigned pods are deployed are excluded, the webhook will not be invoked for those pods. This would allow unsigned images to be admitted without verification. This is a common misconfiguration that can silently bypass enforcement.
- ✗
The public key used by the admission controller is incorrect, causing it to fail open and admit all images.
Why it's wrong here
If the public key is incorrect, the webhook would fail to verify any signature, but it would typically reject images rather than admit them, depending on the webhook's failure policy. Most implementations deny on verification failure. Thus, an incorrect key would likely cause rejections, not admissions of unsigned images.
Go deeper
Related to this question
Learn chapter
Cluster Setup: Secure Configuration and Best Practices
Key term
Admission Controllers
Admission controllers are plugins that intercept and process requests to the Kubernetes API server after authentication and authorization, but before the request is persisted, allowing policies to be enforced on objects being created, modified, or deleted.
Key term
OPA Gatekeeper
OPA Gatekeeper is a Kubernetes admission controller that enforces custom security and compliance policies on resources before they are created or updated in a cluster.
About these practice questions
Courseiva writes every CKS question from scratch — 845 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CNCF exam blueprint
This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.