CKS Supply Chain Security Practice Question
An OPA/Gatekeeper constraint is configured to allow only images from 'trusted-registry.io'. A pod is created with image 'trusted-registry.io/app:v1' but is denied. Which is the MOST likely cause?
⚠ Common exam trap
The CNCF-CKS exam often tests the misconception that image signing or digest pinning is required for registry-based constraints, when in fact the issue is typically a regex mismatch in the OPA policy.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The constraint uses regex and the image does not match the pattern
The most likely cause is that the OPA/Gatekeeper constraint uses a regex pattern to match allowed image registries, and the image 'trusted-registry.io/app:v1' does not match that pattern. Gatekeeper constraints often rely on Rego rules that check image strings against regex patterns; if the pattern is too restrictive or incorrectly defined (e.g., requiring a trailing slash or specific path), valid images can be denied. This is a common misconfiguration where the regex does not account for the full image reference format.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The constraint is only applied in the default namespace
Why it's wrong here
OPA Gatekeeper constraints are defined as custom resources that are inherently cluster-scoped, meaning a constraint object lives in the cluster and applies to all namespaces unless it explicitly uses a namespaceSelector to narrow its scope. Therefore, the idea that a constraint is 'only applied in the default namespace' contradicts Gatekeeper's architecture, as there is no per-namespace constraint instance unless you create separate constraint objects. The denial you are seeing is not caused by namespace restrictions, but by something else entirely.
- ✗
The image tag is not pinned to a digest
Why it's wrong here
The constraint in question is evaluating the image registry path against a regex pattern, not the image tag or digest. While pinning images to a digest is a security best practice that ensures immutability, it does not change the registry string that the constraint's regex is tested against. An image can have a tag or even be pinned to a digest and still be denied if the registry part does not match the allowed pattern, so an unpinned tag is not the reason for the denial.
- ✗
The image is not signed
Why it's wrong here
Image signing (e.g., with cosign) is a separate supply-chain security mechanism that proves the image's integrity and origin, but OPA Gatekeeper constraints that use regex matching on the image string do not consider signatures at all. The constraint is statically checking whether the image reference matches a specific registry pattern; a signed image that does not match that pattern is still denied, and an unsigned image that does match is allowed. Therefore, lack of a signature is not what causes this constraint to deny the image.
- ✓
The constraint uses regex and the image does not match the pattern
Why this is correct
The constraint is built with a regex pattern (or a glob converted to regex) that defines exactly which image registry paths are allowed, and Gatekeeper uses this pattern to match against the full image reference. If the image reference omits a required path segment, uses a different registry host, or otherwise fails to satisfy the regex anchors, the constraint fails and blocks the image. So the denial happens because the image string does not match the precise pattern that the constraint's `allowedPattern` (or similar field) enforces.
Go deeper
Related to this question
About these practice questions
This CKS question is part of Courseiva's 845-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.