Courseiva
Supply Chain Security →mediumMultiple Choice

CKS Supply Chain Security Practice Question

A security engineer wants to integrate image scanning into a CI/CD pipeline. They are using a tool that can scan the filesystem of the build context before building the image. Which tool is best suited for this purpose?

⚠ Common exam trap

The CKS exam often tests the distinction between tools that scan build context filesystems (like Trivy fs) versus tools that scan built container images (like Trivy image or Grype), causing candidates to confuse the pipeline stage where each tool applies.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Trivy (trivy fs)

Trivy's `fs` subcommand scans the filesystem of a build context (directory) for vulnerabilities and misconfigurations before the container image is built. This allows the security engineer to catch issues early in the CI/CD pipeline, such as vulnerable application dependencies or insecure configurations in Dockerfiles, without needing a built image. Trivy is purpose-built for this filesystem scanning use case, making it the correct choice.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Trivy (trivy fs)

    Why this is correct

    Trivy's trivy fs command scans a filesystem directory, such as a Docker build context, for known vulnerabilities by inspecting OS package manager files and language-specific lock files. It matches installed versions against comprehensive vulnerability databases (e.g., NVD, GHSA) and produces a report without requiring a built image. This makes it ideal for shifting security left in CI/CD pipelines, catching vulnerable dependencies before they are baked into a container image.

  • ✗

    Kubesec

    Why it's wrong here

    Kubesec is a static analyzer that evaluates Kubernetes YAML manifests against security best practices, such as whether containers run as root, have privileged access, or lack resource limits. It outputs a risk score and recommendations but does not examine the filesystem for package versions or CVEs. Consequently, it cannot perform vulnerability scanning on a build context, as it focuses purely on the security configuration of manifest objects.

  • ✗

    Notary

    Why it's wrong here

    Notary is a server-side and client-side tool that implements The Update Framework (TUF) to enable trust for remote image repositories. It manages collections of signed metadata to guarantee the integrity and freshness of image tags, allowing consumers to verify that a particular image hasn't been tampered with. However, it does not have any capability to scan the filesystem or image layers for known vulnerabilities; it only ensures authenticity and provenance, not security of the content itself.

  • ✗

    Cosign

    Why it's wrong here

    Cosign is a command-line utility for signing and verifying container images, often used with the Sigstore ecosystem for keyless signing and transparency logs. It allows you to attest to the origin of an image and verify its signature at pull time, which is a supply-chain integrity measure. But Cosign contains no vulnerability database and cannot inspect the filesystem or app dependencies; its only function is to deal with signatures and attestations, not CVE detection.

About these practice questions

Courseiva writes every CKS question from scratch — 845 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.