Courseiva
Supply Chain Security →mediumMultiple Choice

CKS Supply Chain Security Practice Question

An administrator wants to perform static analysis on Kubernetes manifest files to find security misconfigurations. Which tool is specifically designed for this?

⚠ Common exam trap

CNCF often tests the distinction between general-purpose security scanners and purpose-built Kubernetes manifest analyzers. Although Trivy is a popular scanner that includes Kubernetes manifest misconfiguration scanning, it is a broader tool not specifically designed for this task; Kubesec is the dedicated tool for static analysis of Kubernetes YAML manifests. Candidates may choose Trivy due to its popularity, but Kubesec is the correct answer for a tool specifically designed for Kubernetes manifest security.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Kubesec

Kubesec (option C) is specifically designed for static analysis of Kubernetes manifest files to identify security misconfigurations. It evaluates YAML or JSON manifests against a set of built-in security best practices, such as ensuring containers run as non-root, avoiding privileged escalation, and setting read-only root filesystems. While Trivy can also scan Kubernetes manifests for misconfigurations as part of its broader vulnerability and IaC scanning capabilities, Kubesec is purpose-built for Kubernetes manifest security analysis and is the most specific tool among the choices.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Trivy

    Why it's wrong here

    Trivy scans container images, filesystems and repositories for known CVEs and misconfigurations, but its Kubernetes manifest checks are a secondary feature; dedicated static analysers such as kubesec or Checkov parse YAML specifically for security misconfigurations. Trivy is tempting because it does report some IaC issues, and it would be correct for vulnerability scanning of images.

  • ✗

    Cosign

    Why it's wrong here

    Cosign signs and verifies container images and other OCI artefacts, checking signatures and attestations rather than parsing YAML for misconfigured fields such as privileged containers or missing security contexts. It is tempting because it belongs to the same supply-chain security toolset, and it would be correct when verifying image provenance before deployment.

  • ✓

    Kubesec

    Why this is correct

    Kubesec parses manifest YAML directly, without a running cluster, and scores it against security controls such as privileged containers, host namespaces and missing resource limits. That static, file-based scanning satisfies the stem's requirement to find misconfigurations before deployment, unlike runtime admission controllers or cluster-wide audit tools.

  • ✗

    Syft

    Why it's wrong here

    Syft generates a software bill of materials by inventorying packages inside container images or filesystems; it does not parse Kubernetes YAML or flag insecure manifest settings. It is tempting because it examines artefacts for security-relevant content, and it would be correct when cataloguing installed packages and their versions.

About these practice questions

This CKS question is part of Courseiva's 845-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.