CKS Supply Chain Security Practice Question
A user creates a Deployment with image 'alpine:3.18' and the Pod status is 'ErrImagePull'. The admin checks the image policy and sees that only images with SHA digests are allowed. What is the fix?
⚠ Common exam trap
Many candidates confuse admission controllers (like AlwaysPullImages) with image reference policies, or assume that changing to a different tag (like 'latest') will bypass the restriction, when in fact the policy explicitly requires a digest-based reference.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Change the image to 'alpine@sha256:...'
The cluster policy requires images to be identified by SHA digest rather than tags. Using an image reference like 'alpine@sha256:...' ensures the image is pulled by its immutable digest, bypassing tag-based resolution and satisfying the policy. This is a common supply chain security measure to prevent tag mutability and ensure image integrity.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Enable the AlwaysPullImages admission controller
Why it's wrong here
Enabling the AlwaysPullImages admission controller forces the kubelet to set imagePullPolicy: Always on every pod, but it does not rewrite the image reference from a tag to a digest. The policy requiring immutable references still sees alpine:3.18 as a mutable tag, so the deployment would continue to be rejected regardless of the pull policy.
- ✗
Change the image to 'alpine:latest'
Why it's wrong here
Specifying alpine:latest is still a tag, not an immutable reference. Tags are mutable pointers that can be reassigned to a different image at any time, so a policy mandating digest-based references treats latest just like any other tag and will reject it. Using a known immutable digest is the only way to satisfy the requirement.
- ✗
Add a non-root user to the Dockerfile
Why it's wrong here
Adding a non-root user to the Dockerfile changes the runtime user of the container, which is a good security hardening practice, but it has no effect on how the image is referenced by the deployment. The admission policy evaluates the image field's reference format, not the contents of the image, so the mutable tag alpine:3.18 remains invalid.
- ✓
Change the image to 'alpine@sha256:...'
Why this is correct
Changing the image to alpine@sha256:... provides a content-addressable reference that uniquely pins the image manifest to its cryptographic digest. This mutability is eliminated: even if the original tag is moved, the deployment will always pull the exact verified image, and this format precisely satisfies the immutable-reference policy.
Go deeper
Related to this question
About these practice questions
This CKS question is part of Courseiva's 845-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on CKS
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. A developer wants to ensure that a pod always uses a specific version of an image that cannot be changed without updating the manifest. Which image reference should be used?
medium- ✓ A.myimage@sha256:abcdef...
- B.myimage:latest
- C.myimage:v1.0
- D.myimage:1.0.0
Why A: (myimage@sha256:abcdef...) uses a digest-based image reference, which pins the image to an immutable content hash. This ensures that the exact same image is always pulled, regardless of tag updates, and any change to the image would require updating the manifest. This aligns with the requirement that the image version cannot be changed without modifying the manifest.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.