CKS Supply Chain Security Practice Question
A security engineer wants to enforce that all images in the cluster must come from a trusted registry 'trusted-registry.io'. They are using OPA/Gatekeeper. Which constraint template and constraint combination would achieve this?
⚠ Common exam trap
The CKS exam often tests the difference between 'contains' and 'startswith' in Rego policies, where candidates mistakenly choose 'contains' thinking it is sufficient, but it fails to prevent images from untrusted registries that include the trusted string in their path.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
A constraint template that checks 'spec.containers[*].image' starts with 'trusted-registry.io/' and a constraint that denies if it does not.
The constraint template must enforce that container images originate from the trusted registry by checking that the image string starts with 'trusted-registry.io/'. This ensures that only images from that specific registry are allowed, and the constraint denies any pod that does not meet this condition. OPA/Gatekeeper uses Rego policies to evaluate the image field and reject non-compliant resources during admission control.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
A constraint template that checks 'spec.containers[*].image' contains 'trusted-registry.io' and a constraint that denies if it does.
Why it's wrong here
Substring matching on 'contains' admits spoofed registries such as trusted-registry.io.attacker.com, so the trust boundary is not actually enforced. It is tempting because it tolerates repository paths and tags after the registry name, and would be correct if the stem demanded only that the string appear somewhere in the image reference.
- ✗
A constraint template that allows all images and a constraint that audits violations.
Why it's wrong here
A template that allows everything enforces nothing; the constraint merely reports violations, so untrusted images still admit and run. It is tempting because audit mode is the safe first rollout step before switching to deny, and would be correct when the requirement is visibility rather than enforcement.
- ✓
A constraint template that checks 'spec.containers[*].image' starts with 'trusted-registry.io/' and a constraint that denies if it does not.
Why this is correct
Gatekeeper's `K8sAllowedRepos` template evaluates each container's `image` field against an allowed-prefix list, denying any pod whose image does not begin with `trusted-registry.io/`. This directly satisfies the stem's constraint that every image originate from the trusted registry, enforced at admission before workloads are created.
- ✗
A constraint template that checks 'spec.containers[*].image' equals 'trusted-registry.io' and a constraint that denies if it does not.
Why it's wrong here
Equality against the bare string 'trusted-registry.io' fails because image references include registry, repository and tag, so every legitimate image is denied. It is tempting as the strictest reading of 'must come from', and would suit a field holding exactly one permitted literal value, not image paths.
Go deeper
Related to this question
About these practice questions
One of 845 original CKS practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.