CKS Supply Chain Security Practice Question
An administrator wants to enforce that only images signed by a trusted key can run in the cluster. They have configured cosign and want to use a Kubernetes admission controller. Which tool should they deploy?
⚠ Common exam trap
Watch out — candidates often confuse tools like Helm or Prometheus with admission controllers, but only Kyverno (or OPA/Gatekeeper with custom rules) can enforce image signature verification via Cosign at the admission webhook level.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Kyverno with a verifyImages rule
Kyverno is a Kubernetes-native policy engine that can enforce admission controls via policies. Its `verifyImages` rule uses Cosign to check that container images are signed with a trusted public key before allowing them to run, making it the correct tool for this use case.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Helm
Why it's wrong here
Helm is a package manager that simplifies deploying applications by templating Kubernetes manifests. It operates during the installation phase, but it has no admission control hooks to validate or enforce image signature policies on workloads after manifests are submitted. Helm cannot intercept pod creation to verify cosign signatures, so it is not a tool for enforcing signed-image admission.
- ✗
Kube-bench
Why it's wrong here
Kube-bench is a security auditor that runs checks from the CIS Kubernetes Benchmark to assess configuration compliance. It produces a report of failed tests, such as insecure API server settings, but it does not run as an admission controller and cannot reject resources. Since it only audits and cannot enforce policies live, it cannot guarantee that only signed images are admitted.
- ✗
Prometheus
Why it's wrong here
Prometheus collects metrics and alerts on cluster health, performance, and events through its scraping model. It is an observability tool that does not participate in the Kubernetes admission request lifecycle, so it cannot evaluate or block incoming pod specs. Without an admission webhook or policy engine, Prometheus has no mechanism to enforce image signature requirements.
- ✓
Kyverno with a verifyImages rule
Why this is correct
Kyverno is a purpose-built policy engine that functions as a dynamic admission controller in the API request path. Its verifyImages rule integrates with Sigstore/cosign to check an image's cryptographic signature against configured public keys or Keyless authorities, and it can reject or patch any Pod that uses an unsigned or improperly signed image. Kyverno's rule can be scoped to namespaces and supports both failure modes, making it the appropriate tool to enforce this requirement.
Go deeper
Related to this question
Learn chapter
Cluster Hardening: Node and Container Security
Key term
Pod Security Admission
Pod Security Admission is a Kubernetes feature that enforces security standards on pods at creation time to prevent running containers with dangerous privileges.
Key term
Kyverno Policy Engine
Kyverno Policy Engine is a Kubernetes-native tool that enforces rules on resources to ensure security, compliance, and best practices across your cluster.
About these practice questions
This CKS question is part of Courseiva's 845-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on CKS
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. An administrator wants to ensure that only signed container images are deployed in the cluster. Which admission controller can be used to enforce this policy?
medium- A.ServiceAccount
- B.AlwaysPullImages
- ✓ C.ImagePolicyWebhook
- D.NodeRestriction
Why C: The ImagePolicyWebhook admission controller allows a cluster to enforce a policy that only signed container images are deployed by intercepting image creation requests and validating them against an external webhook. This webhook can check image signatures (e.g., using Notary or Cosign) before admitting the pod, making it the correct choice for enforcing signed image policies.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.