Courseiva
Supply Chain Security →mediumMultiple Choice

CKS Supply Chain Security Practice Question

A security engineer runs 'kubesec scan deployment.yaml' and receives a score of -1. What does this score indicate?

⚠ Common exam trap

The CKS exam often tests the distinction between error codes and security scores; the trap here is that candidates assume -1 means 'worst security' (like a negative vulnerability score) rather than recognizing it as a sentinel value for scan failure.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The scan failed due to an error or invalid YAML

In kubesec, a score of -1 indicates that the scan could not complete successfully, typically due to an error in the YAML file (e.g., invalid syntax, malformed structure) or a failure in the scanning process itself. Kubesec returns scores from 0 to 10 for valid deployments, where higher scores indicate better security; -1 is a special sentinel value reserved for scan failures, not a security assessment.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The deployment passed all security checks

    Why it's wrong here

    A valid kubesec scan produces a numeric score, typically from 0 to 10, representing the number of security checks passed. A score of -1 is a sentinel value specifically reserved for errors, such as invalid YAML syntax, an unreadable file, or a failure to parse the Kubernetes manifest. Therefore, this deployment could not be evaluated, and claiming it 'passed all security checks' is incorrect; the tool failed before it could run any checks.

  • ✗

    The deployment is not secure and needs immediate attention

    Why it's wrong here

    Kubesec does evaluate insecure practices, such as running containers as root or allowing privilege escalation, and would return a low but non-negative score in such cases. However, a score of -1 means the scanner crashed or encountered malformed input, so no security analysis was performed at all. The correct response is to fix the YAML parsing error and re-run the scan, not to treat the deployment as having been assessed and found wanting.

  • ✓

    The scan failed due to an error or invalid YAML

    Why this is correct

    The kubesec CLI returns a score of -1 when it cannot complete a scan, typically because the input is invalid YAML, the file cannot be read, or the manifest is missing required fields. This is explicitly defined as a scan failure, not a security score. In practice, you should verify the deployment YAML with a YAML linter or run kubesec with verbose output to see the underlying parse error before concluding anything about the security posture.

  • ✗

    The deployment has critical vulnerabilities

    Why it's wrong here

    Kubesec is a static analysis tool that checks for adherence to Kubernetes security best practices (e.g., pod security context, container resource limits); it is not a vulnerability scanner and does not report CVEs. A -1 score is an error indicator, not a critical finding or a severity rating. The deployment may or may not have security issues, but the immediate problem is that the scan itself failed.

About these practice questions

One of 845 original CKS practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.