Courseiva
Supply Chain Security →mediumMultiple Choice

CKS Supply Chain Security Practice Question

A security policy requires that all container images must be signed using Cosign. Which admission controller enforces signature verification at pod creation time?

⚠ Common exam trap

The CKS exam often tests the distinction between generic webhooks (MutatingAdmissionWebhook, ValidatingAdmissionWebhook) and purpose-built admission controllers like ImagePolicyWebhook, leading candidates to incorrectly choose ValidatingAdmissionWebhook because they assume any validation can be done there, missing that ImagePolicyWebhook is the specific controller for image signature enforcement.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

ImagePolicyWebhook

The ImagePolicyWebhook admission controller is the correct choice because it is specifically designed to enforce image signature verification at pod creation time. It intercepts pod creation requests and queries an external webhook (e.g., a Cosign-based policy engine) to validate that the container image has a valid cryptographic signature before allowing the pod to be admitted. This directly meets the requirement for Cosign-based signature enforcement.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    ImagePolicyWebhook

    Why this is correct

    ImagePolicyWebhook is the dedicated Kubernetes admission controller that evaluates container image policies at pod creation time. It is enabled via --enable-admission-plugins and reads an external webhook configuration file; for every Pod that references images, the API server sends an ImageReview request containing the image names, and the webhook returns an allowed/denied verdict with a reason. This integrates with external image verification services such as Sigstore/cosign or Notary to enforce signature checks, making it the built-in, purpose-specific mechanism for this requirement.

  • ✗

    MutatingAdmissionWebhook

    Why it's wrong here

    MutatingAdmissionWebhook is the generic admission webhook meant to modify API objects before they are persisted, such as injecting sidecars or setting defaults. It does not contain any image-signature or image-policy evaluation logic; while you could theoretically write a custom webhook server that performs image checks and patches or rejects objects, doing so would require building and operating an entire external verification pipeline rather than using a platform-provided policy controller. It is therefore not the correct choice for enforcing a required image signature policy.

  • ✗

    ValidatingAdmissionWebhook

    Why it's wrong here

    ValidatingAdmissionWebhook is a general-purpose admission webhook that validates arbitrary resource requests and can reject or accept them, but it is not image-policy-aware. Unlike ImagePolicyWebhook, it does not define the ImageReview API or provide a standard request/response structure for image metadata, so enforcing 'all images must be signed' would depend on a custom implementation that inspects pod spec fields and uses its own registry verification logic. It is a tool you could misuse for this job, not the purpose-built admission controller the requirement demands.

  • ✗

    ResourceQuota

    Why it's wrong here

    ResourceQuota is a Kubernetes API object that limits aggregate resource usage within a namespace, such as total CPU, memory, or the count of Pods and PersistentVolumeClaims. It operates on declarative quota values and has no mechanism to inspect the contents of container images, validate their signatures, or reason about their provenance. Therefore it cannot enforce a security policy requiring that all images be verified before use.

Go deeper

Related to this question

About these practice questions

Courseiva writes every CKS question from scratch — 845 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.