CKS Supply Chain Security Practice Question
An admin wants to scan a local filesystem for vulnerabilities using Trivy. Which command should they use?
⚠ Common exam trap
Candidates often confuse `trivy image` (for container images) with `trivy fs` (for filesystems), or assume `trivy config` covers all local scanning, when in fact each subcommand targets a distinct artifact type.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
trivy fs
`trivy fs` scans a local filesystem for vulnerabilities, misconfigurations, and secrets. This command is specifically designed to analyze directories and files on disk, making it the appropriate choice for scanning a local filesystem as described in the question.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
trivy image
Why it's wrong here
`trivy image` is designed to scan container images by analyzing their layers and metadata, typically from a registry or a local Docker daemon. It requires an image reference and does not accept an arbitrary filesystem path, so it cannot be used to scan a local directory or mounted volume for vulnerabilities.
- ✗
trivy config
Why it's wrong here
`trivy config` evaluates Infrastructure-as-Code files such as Terraform, CloudFormation, and Kubernetes manifests for misconfigurations, not for OS or application CVEs. It is a separate scanning mode from vulnerability detection, and running it on a local filesystem would report configuration issues (or nothing) rather than known vulnerabilities in packages. Furthermore, the correct syntax for filesystem scanning is `trivy fs`, not `trivy config`.
- ✓
trivy fs
Why this is correct
`trivy fs` is the correct subcommand to scan a local filesystem, as it takes a directory path and analyzes OS packages, language-specific dependencies, and other artifacts against Trivy's vulnerability database. It works without a container runtime and can be pointed at a source tree or a whole root filesystem, making it ideal for CI pipelines or vulnerability audits of a machine.
- ✗
trivy repo
Why it's wrong here
`trivy repo` is intended for scanning Git repositories, typically by specifying a remote URL that Trivy clones before running its analyzers. It does not directly scan local filesystem paths; while you can pass a local git repository directory, the command's focus is on repository-level analysis, and for a plain local path the intended tool is `trivy fs`.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CKS question from scratch — 845 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.