Courseiva
Supply Chain Security →mediumMultiple Choice

CKS Supply Chain Security Practice Question

An administrator wants to verify that an image was signed by a specific key before deploying. Which Cosign command should be used?

⚠ Common exam trap

CNCF often tests the distinction between signing (`cosign sign`) and verifying (`cosign verify`), expecting candidates to know that `verify` is the correct command for checking an image's signature before deployment, not `sign` or `attest`.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

cosign verify --key mykey.pub myimage

The `cosign verify` command is used to verify the signature of a container image against a public key. By specifying `--key mykey.pub`, the administrator confirms that the image was signed with the corresponding private key before it can be deployed, ensuring supply chain integrity.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    cosign verify --key mykey.pub myimage

    Why this is correct

    The `cosign verify` command retrieves the image's signature artifacts from the registry and cryptographically verifies them against the specified public key. It recomputes the image digest from the manifest and checks that the signed payload matches, ensuring the image has not been modified. A successful exit status indicates the signature is valid and trusted, confirming the image was signed by the holder of the corresponding private key. This is the appropriate command for an administrator to verify provenance before deployment.

  • ✗

    cosign sign --key mykey.pub myimage

    Why it's wrong here

    The `cosign sign` subcommand is used to generate and attach a new signature to an image, not to validate an existing one. It requires a private key (or a key reference suitable for signing) to create the cryptographic signature; supplying a public key with `--key mykey.pub` would either be rejected or fail because public keys cannot produce signatures. Therefore, this command cannot tell the administrator whether an image was already signed, and using it would not perform any verification. In fact, attempting to sign with a public key is a common error.

  • ✗

    cosign download myimage

    Why it's wrong here

    The `cosign download` command simply fetches the stored signatures, attestations, or SBOMs associated with an image from the registry and prints them to stdout. It performs no cryptographic validation—it does not check whether the signature is signed by a trusted key or matches the image digest. While useful for manual inspection or debugging, it cannot confirm authenticity or integrity, so it fails as a verification tool. An administrator would need a separate verification step to establish trust.

  • ✗

    cosign attest --predicate mypredicate myimage

    Why it's wrong here

    The `cosign attest` command creates a new in-toto attestation (e.g., SLSA provenance) for an image and signs it with a private key, then attaches it to the registry. The `--predicate` flag supplies the attestation content; it does not trigger any checking of existing signatures. It is a signing operation, not a verification operation, and it requires a private key rather than a public key to run. Thus, it cannot be used to verify that an image was signed by someone else.

About these practice questions

This CKS question is part of Courseiva's 845-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.