CKS Supply Chain Security Practice Question
A security policy requires that all container images must reference a specific SHA256 digest instead of a tag. You need to enforce this using Kyverno. Which Kyverno rule type and pattern would you use?
⚠ Common exam trap
The CKS exam often tests the distinction between validation and mutation rules, where candidates mistakenly choose a mutate rule to 'fix' the image reference instead of a validate rule to enforce the policy as written.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
A validate rule with a pattern that the image field matches '@sha256:'
Kyverno's validate rules with a pattern can enforce that the image field in a Pod spec contains '@sha256:', ensuring only digest-based references are used. This directly meets the security policy requirement without altering the image reference or relying on external data.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
A generate rule that creates a ConfigMap with allowed digests
Why it's wrong here
A Kyverno generate rule is designed to create or update a resource when a trigger resource is processed, not to evaluate the contents of the admission request. Generating a ConfigMap that lists allowed digests would simply add a static data object to the cluster; it would not block or flag a Pod whose image lacks a digest. Since the rule never inspects or asserts on the Pod's image field, it cannot satisfy a policy that requires every container image to use a digest.
- ✗
A mutate rule that replaces the image tag with a digest
Why it's wrong here
A mutate rule can rewrite the image field, but this policy is specifically about validating what is already present in the request, not silently fixing it. Replacing a tag with a digest would require a registry lookup to determine the correct digest, which is unreliable and not guaranteed to match the digest that the image would eventually pull. Moreover, allowing the admission to succeed after mutation would let a user submit a non-compliant image and have the policy erase the violation, defeating the requirement that all images must explicitly reference a digest.
- ✓
A validate rule with a pattern that the image field matches '@sha256:'
Why this is correct
A validate rule is the correct Kyverno mechanism because it asserts that the incoming resource matches a required pattern and rejects it otherwise. The pattern `spec.containers[*].image: "*@sha256:*"` enforces that every container image reference includes the immutable digest identifier, since a valid digest always appears as the `@sha256:` suffix. This directly implements the security policy at admission time, ensuring only images with explicit digests are deployed.
- ✗
A validate rule checking the annotation 'image.openshift.io/triggers'
Why it's wrong here
The `image.openshift.io/triggers` annotation is an OpenShift construct used to define ImageStreamTriggers that automatically update a deployment when a tagged image changes; it is not part of the standard Pod image specification. Checking this annotation would not examine the actual `image` fields of the containers, and in a vanilla Kubernetes or even an OpenShift cluster with no triggers the annotation would be absent, causing false failures or false passes. The policy's requirement concerns the container image digest, so evaluating an unrelated OpenShift-specific annotation is both off-target and non-portable.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CKS question from scratch — 845 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.