Courseiva
Supply Chain Security →mediumMultiple Choice

CKS Supply Chain Security Practice Question

A security policy requires that all container images use SHA-based digests instead of tags. Which approach ensures this in a Deployment YAML?

⚠ Common exam trap

The CKS exam often tests the misconception that a separate `digest` field exists in the Kubernetes API, when in reality the digest must be appended to the image name using the `@sha256:` syntax.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Use the image field with a digest, e.g., 'image: nginx@sha256:abc123'

Kubernetes supports using a SHA-based digest in the `image` field, which ensures the exact image content is pulled regardless of tag changes. By specifying the image as `nginx@sha256:abc123`, the container runtime fetches the image by its immutable digest, guaranteeing supply chain integrity and compliance with the security policy.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Use the 'image' field with a tag and also set 'digest' field

    Why it's wrong here

    Kubernetes has no separate digest field in the container spec; only the image string accepts a digest, so this manifest is invalid and never enforces SHA pinning. It is tempting because separating tag and digest appears tidy, and a digest field would be correct if the API actually supported one.

  • ✗

    Set imagePullPolicy: Always and use tags

    Why it's wrong here

    imagePullPolicy governs when the kubelet fetches an image; it does not alter the reference format, so tags remain mutable and the digest requirement is unmet. It is tempting because Always forces fresh pulls, and that policy is correct when you need the newest tag on every pod start.

  • ✓

    Use the image field with a digest, e.g., 'image: nginx@sha256:abc123'

    Why this is correct

    Referencing the image by its sha256 digest pins the exact immutable manifest, so Kubernetes pulls precisely that content. Tags are mutable and can be repointed, so the digest form is the only field syntax that satisfies the SHA-based digest policy.

  • ✗

    Set imagePullPolicy: IfNotPresent and use tags

    Why it's wrong here

    IfNotPresent controls pull timing only and leaves the tag reference mutable, so a retagged image can still be deployed, violating the SHA-digest policy. It is tempting because it reduces registry traffic, and this policy is correct when images are immutable and you want to avoid redundant pulls.

About these practice questions

This CKS question is part of Courseiva's 845-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.