CKS Supply Chain Security Practice Question
An administrator wants to ensure that a Deployment uses a specific image digest (SHA256) instead of a tag. Which field in the Deployment YAML should be modified?
⚠ Common exam trap
Kubernetes often tests the distinction between image reference (`image` field) and image pull behavior (`imagePullPolicy`), trapping candidates who confuse 'how to pull' with 'what to pull'.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
spec.template.spec.containers[].image
The `image` field under `spec.template.spec.containers[]` is where you specify the container image, and to enforce immutable deployment, you replace the tag with the SHA256 digest (e.g., `nginx@sha256:abc123...`). This ensures the exact image content is used, preventing tag mutation or accidental updates.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
spec.replicas
Why it's wrong here
spec.replicas determines the desired number of Pod replicas for the Deployment, so it only affects horizontal scaling. It does not influence which container image is used; the image is defined inside the Pod template. Modifying replicas will increase or decrease Pod count but cannot change the Deployment to a specific image digest or tag. Thus, it is not the field that ensures a particular image is used.
- ✗
spec.template.spec.containers[].imagePullPolicy
Why it's wrong here
imagePullPolicy controls when the kubelet pulls the image: Always, IfNotPresent, or Never. It does not specify the image reference itself; even with Always, the pull is based on whatever image is already set in the container spec. Changing this policy merely changes pull behavior and cannot pin the Deployment to a specific image digest. To guarantee a distinct image, you must update the image field, not the pull policy.
- ✓
spec.template.spec.containers[].image
Why this is correct
The spec.template.spec.containers[].image field accepts a full image reference, and using a digest (e.g., 'image@sha256:...') makes the reference immutable and content-addressed. Unlike tags, a digest uniquely identifies the exact image manifest, ensuring every Pod from this Deployment runs the exact same container build. This is the correct way to constrain a Deployment to a specific image, overriding any mutable tag in the registry. It also prevents accidental or malicious tag overwrites from affecting the running workload.
- ✗
spec.template.metadata.annotations
Why it's wrong here
annotations are metadata key-value pairs attached to the Pod template, often used by tools, metrics, or informational purposes. They have no effect on the container image selection or runtime execution; the kubelet and container runtime ignore them for image resolution. Adding or changing an annotation cannot alter the image reference used to start containers. Therefore, it cannot be used to ensure a specific image is utilized.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CKS question from scratch — 845 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.