CKS Supply Chain Security Practice Question
An administrator wants to verify that an image was signed by a specific key before deploying. Which Cosign command should be used?
⚠ Common exam trap
CNCF often tests the distinction between signing (`cosign sign`) and verifying (`cosign verify`), expecting candidates to know that `verify` is the correct command for checking an image's signature before deployment, not `sign` or `attest`.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
cosign verify --key mykey.pub myimage
The `cosign verify` command is used to verify the signature of a container image against a public key. By specifying `--key mykey.pub`, the administrator confirms that the image was signed with the corresponding private key before it can be deployed, ensuring supply chain integrity.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
cosign verify --key mykey.pub myimage
Why this is correct
The `cosign verify` command retrieves the image's signature artifacts from the registry and cryptographically verifies them against the specified public key. It recomputes the image digest from the manifest and checks that the signed payload matches, ensuring the image has not been modified. A successful exit status indicates the signature is valid and trusted, confirming the image was signed by the holder of the corresponding private key. This is the appropriate command for an administrator to verify provenance before deployment.
- ✗
cosign sign --key mykey.pub myimage
Why it's wrong here
The `cosign sign` subcommand is used to generate and attach a new signature to an image, not to validate an existing one. It requires a private key (or a key reference suitable for signing) to create the cryptographic signature; supplying a public key with `--key mykey.pub` would either be rejected or fail because public keys cannot produce signatures. Therefore, this command cannot tell the administrator whether an image was already signed, and using it would not perform any verification. In fact, attempting to sign with a public key is a common error.
- ✗
cosign download myimage
Why it's wrong here
The `cosign download` command simply fetches the stored signatures, attestations, or SBOMs associated with an image from the registry and prints them to stdout. It performs no cryptographic validation—it does not check whether the signature is signed by a trusted key or matches the image digest. While useful for manual inspection or debugging, it cannot confirm authenticity or integrity, so it fails as a verification tool. An administrator would need a separate verification step to establish trust.
- ✗
cosign attest --predicate mypredicate myimage
Why it's wrong here
The `cosign attest` command creates a new in-toto attestation (e.g., SLSA provenance) for an image and signs it with a private key, then attaches it to the registry. The `--predicate` flag supplies the attestation content; it does not trigger any checking of existing signatures. It is a signing operation, not a verification operation, and it requires a private key rather than a public key to run. Thus, it cannot be used to verify that an image was signed by someone else.
Go deeper
Related to this question
Learn chapter
Supply Chain Security: Policy Enforcement and Admission Controllers
Key term
Image Signing and Verification
Image signing and verification is the process of digitally signing a container image to prove its origin and integrity, and then checking that signature before using the image to ensure it was not tampered with.
About these practice questions
This CKS question is part of Courseiva's 845-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.