CKS Supply Chain Security Practice Question
A security engineer needs to verify that a container image pulled from a private registry was signed by the organization's authorized build pipeline before allowing it to run in the cluster. The signatures are stored alongside the image in the OCI registry. Which command should the engineer use to perform this verification?
⚠ Common exam trap
It's easy for candidates to confuse signing operations with verification, assuming that any cosign command involving signatures will check authenticity.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
cosign verify --key cosign.pub registry.example.com/app:1.2.3
To verify an image's signature in an OCI registry, cosign verify is the correct command. It uses the public key to validate the signature, ensuring the image was signed by the trusted private key. This step is critical in a supply chain security workflow to prevent running unauthorized or tampered images.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
cosign verify --key cosign.pub registry.example.com/app:1.2.3
Why this is correct
This command uses the cosign public key to verify the signature attached to the image in the OCI registry. It checks that the image was signed by the corresponding private key, ensuring authenticity and integrity before deployment. This directly addresses the requirement to confirm the image was signed by the authorized pipeline.
- ✗
cosign sign --key cosign.key registry.example.com/app:1.2.3
Why it's wrong here
This command signs the image using a private key, which is the action performed by the build pipeline, not the verification step. It would create a new signature rather than validate an existing one. The engineer needs to verify, not sign, so this does not meet the requirement.
- ✗
cosign attach signature --signature sig.json registry.example.com/app:1.2.3
Why it's wrong here
This command attaches a detached signature to an image in the registry. It is used when manually associating a signature with an image, not for verification. It does not validate the signature against a public key, so it fails to confirm the image's authenticity as required.
- ✗
cosign generate-key-pair
Why it's wrong here
This command generates a new public/private key pair for cosign. It does not verify any existing signatures on an image. While key generation is part of setting up cosign, it is unrelated to the immediate need to verify an image's signature before deployment.
Go deeper
Related to this question
Learn chapter
Cluster Setup: Secure Configuration and Best Practices
Key term
Image Signing and Verification
Image signing and verification is the process of digitally signing a container image to prove its origin and integrity, and then checking that signature before using the image to ensure it was not tampered with.
About these practice questions
One of 845 original CKS practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CNCF exam blueprint
This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.