CKS Supply Chain Security Practice Question
A security policy requires that all container images use SHA-based digests instead of tags. Which approach ensures this in a Deployment YAML?
⚠ Common exam trap
The CKS exam often tests the misconception that a separate `digest` field exists in the Kubernetes API, when in reality the digest must be appended to the image name using the `@sha256:` syntax.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use the image field with a digest, e.g., 'image: nginx@sha256:abc123'
Kubernetes supports using a SHA-based digest in the `image` field, which ensures the exact image content is pulled regardless of tag changes. By specifying the image as `nginx@sha256:abc123`, the container runtime fetches the image by its immutable digest, guaranteeing supply chain integrity and compliance with the security policy.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Use the 'image' field with a tag and also set 'digest' field
Why it's wrong here
Kubernetes has no separate digest field in the container spec; only the image string accepts a digest, so this manifest is invalid and never enforces SHA pinning. It is tempting because separating tag and digest appears tidy, and a digest field would be correct if the API actually supported one.
- ✗
Set imagePullPolicy: Always and use tags
Why it's wrong here
imagePullPolicy governs when the kubelet fetches an image; it does not alter the reference format, so tags remain mutable and the digest requirement is unmet. It is tempting because Always forces fresh pulls, and that policy is correct when you need the newest tag on every pod start.
- ✓
Use the image field with a digest, e.g., 'image: nginx@sha256:abc123'
Why this is correct
Referencing the image by its sha256 digest pins the exact immutable manifest, so Kubernetes pulls precisely that content. Tags are mutable and can be repointed, so the digest form is the only field syntax that satisfies the SHA-based digest policy.
- ✗
Set imagePullPolicy: IfNotPresent and use tags
Why it's wrong here
IfNotPresent controls pull timing only and leaves the tag reference mutable, so a retagged image can still be deployed, violating the SHA-digest policy. It is tempting because it reduces registry traffic, and this policy is correct when images are immutable and you want to avoid redundant pulls.
Go deeper
Related to this question
About these practice questions
This CKS question is part of Courseiva's 845-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.