CKS Supply Chain Security Practice Question
An administrator wants to perform static analysis on Kubernetes manifest files to find security misconfigurations. Which tool is specifically designed for this?
⚠ Common exam trap
CNCF often tests the distinction between general-purpose security scanners and purpose-built Kubernetes manifest analyzers. Although Trivy is a popular scanner that includes Kubernetes manifest misconfiguration scanning, it is a broader tool not specifically designed for this task; Kubesec is the dedicated tool for static analysis of Kubernetes YAML manifests. Candidates may choose Trivy due to its popularity, but Kubesec is the correct answer for a tool specifically designed for Kubernetes manifest security.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Kubesec
Kubesec (option C) is specifically designed for static analysis of Kubernetes manifest files to identify security misconfigurations. It evaluates YAML or JSON manifests against a set of built-in security best practices, such as ensuring containers run as non-root, avoiding privileged escalation, and setting read-only root filesystems. While Trivy can also scan Kubernetes manifests for misconfigurations as part of its broader vulnerability and IaC scanning capabilities, Kubesec is purpose-built for Kubernetes manifest security analysis and is the most specific tool among the choices.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Trivy
Why it's wrong here
Trivy scans container images, filesystems and repositories for known CVEs and misconfigurations, but its Kubernetes manifest checks are a secondary feature; dedicated static analysers such as kubesec or Checkov parse YAML specifically for security misconfigurations. Trivy is tempting because it does report some IaC issues, and it would be correct for vulnerability scanning of images.
- ✗
Cosign
Why it's wrong here
Cosign signs and verifies container images and other OCI artefacts, checking signatures and attestations rather than parsing YAML for misconfigured fields such as privileged containers or missing security contexts. It is tempting because it belongs to the same supply-chain security toolset, and it would be correct when verifying image provenance before deployment.
- ✓
Kubesec
Why this is correct
Kubesec parses manifest YAML directly, without a running cluster, and scores it against security controls such as privileged containers, host namespaces and missing resource limits. That static, file-based scanning satisfies the stem's requirement to find misconfigurations before deployment, unlike runtime admission controllers or cluster-wide audit tools.
- ✗
Syft
Why it's wrong here
Syft generates a software bill of materials by inventorying packages inside container images or filesystems; it does not parse Kubernetes YAML or flag insecure manifest settings. It is tempting because it examines artefacts for security-relevant content, and it would be correct when cataloguing installed packages and their versions.
Go deeper
Related to this question
About these practice questions
This CKS question is part of Courseiva's 845-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.