Courseiva
Supply Chain Security →mediumMultiple Choice

CKS Supply Chain Security Practice Question

An admin wants to scan a local filesystem for vulnerabilities using Trivy. Which command should they use?

⚠ Common exam trap

Candidates often confuse `trivy image` (for container images) with `trivy fs` (for filesystems), or assume `trivy config` covers all local scanning, when in fact each subcommand targets a distinct artifact type.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

trivy fs

`trivy fs` scans a local filesystem for vulnerabilities, misconfigurations, and secrets. This command is specifically designed to analyze directories and files on disk, making it the appropriate choice for scanning a local filesystem as described in the question.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    trivy image

    Why it's wrong here

    `trivy image` is designed to scan container images by analyzing their layers and metadata, typically from a registry or a local Docker daemon. It requires an image reference and does not accept an arbitrary filesystem path, so it cannot be used to scan a local directory or mounted volume for vulnerabilities.

  • ✗

    trivy config

    Why it's wrong here

    `trivy config` evaluates Infrastructure-as-Code files such as Terraform, CloudFormation, and Kubernetes manifests for misconfigurations, not for OS or application CVEs. It is a separate scanning mode from vulnerability detection, and running it on a local filesystem would report configuration issues (or nothing) rather than known vulnerabilities in packages. Furthermore, the correct syntax for filesystem scanning is `trivy fs`, not `trivy config`.

  • ✓

    trivy fs

    Why this is correct

    `trivy fs` is the correct subcommand to scan a local filesystem, as it takes a directory path and analyzes OS packages, language-specific dependencies, and other artifacts against Trivy's vulnerability database. It works without a container runtime and can be pointed at a source tree or a whole root filesystem, making it ideal for CI pipelines or vulnerability audits of a machine.

  • ✗

    trivy repo

    Why it's wrong here

    `trivy repo` is intended for scanning Git repositories, typically by specifying a remote URL that Trivy clones before running its analyzers. It does not directly scan local filesystem paths; while you can pass a local git repository directory, the command's focus is on repository-level analysis, and for a plain local path the intended tool is `trivy fs`.

About these practice questions

Courseiva writes every CKS question from scratch — 845 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.