CKS Supply Chain Security Practice Question
An organization uses a GitOps workflow with Argo CD to deploy applications to Kubernetes. The security team wants to ensure that container images are immutable and signed. They currently use a private container registry (Harbor) with vulnerability scanning and Cosign for signing. Which combination of controls best enforces that only signed and scanned images are deployed?
⚠ Common exam trap
CNCF often tests the concept that imagePullSecrets only handle authentication, not integrity or signing, leading candidates to mistakenly choose Option B as a security control.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Enable Harbor's content trust feature to reject unsigned images, and use a Kyverno admission rule to verify Cosign signatures at deploy time.
It enforces a two-layer defense: Harbor's content trust rejects unsigned images at the registry level, and a Kyverno admission rule verifies Cosign signatures at deploy time. This ensures that even if an unsigned image bypasses the registry, it will be blocked by Kubernetes admission control, providing defense in depth for supply chain security.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Configure Argo CD to verify Cosign signatures before syncing the application.
Why it's wrong here
Argo CD is a GitOps controller that reconciles state from Git, but it has no built-in support for verifying Cosign signatures on container images. While external integrations or plugins might be added, the native sync process will not inspect image signatures, so unsigned images could still be deployed. Additionally, Argo CD only manages applications it is configured to sync, leaving non-GitOps or direct deployments outside its protective scope.
- ✗
Use imagePullSecrets in Kubernetes to ensure only Harbor images are used.
Why it's wrong here
imagePullSecrets merely provide Kubernetes with credentials to authenticate to a private registry like Harbor; they do not inspect the image's signature, trust status, or vulnerability scan results. An imagePullSecret will happily pull an unsigned or compromised image if the credentials are valid, because it only handles authentication and not content assurance. Therefore, while imagePullSecrets are necessary for private registry access, they do nothing to enforce a signature or scanning policy.
- ✗
Add a Cosign verification step in the CI pipeline before pushing images to Harbor, and rely on that guarantee.
Why it's wrong here
Adding a Cosign verification step in the CI pipeline ensures that images built through your official pipeline are signed before being pushed to Harbor, but it provides no protection against direct pushes to the registry. If an attacker compromises registry credentials or has insider access, they can push an unsigned or malicious image that bypasses the CI check entirely. Since Kubernetes does not re-verify the signature at runtime or deploy time, relying solely on CI verification leaves a critical supply chain gap that should be closed by registry-side enforcement and admission control.
- ✓
Enable Harbor's content trust feature to reject unsigned images, and use a Kyverno admission rule to verify Cosign signatures at deploy time.
Why this is correct
Enabling Harbor's content trust feature causes the registry to reject pushes of unsigned images, meaning only images that carry the required signature can be stored and later pulled. A Kyverno admission rule with a `verifyImages` check validates the Cosign signature again at the moment Kubernetes attempts to create a Pod, so even if an image is replaced or a signed tag is moved to a different digest, the admission controller blocks it. Together these enforce signature integrity at both the registry boundary and the cluster boundary, providing defense-in-depth that a single control cannot achieve.
Go deeper
Related to this question
Learn chapter
Cluster Setup: Secure Configuration and Best Practices
Key term
Image Signing and Verification
Image signing and verification is the process of digitally signing a container image to prove its origin and integrity, and then checking that signature before using the image to ensure it was not tampered with.
Key term
Image Scanning
Image scanning is the automated process of inspecting container images for known vulnerabilities, misconfigurations, and malware before they are deployed into production environments.
About these practice questions
One of 845 original CKS practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.