Courseiva
Supply Chain Security →hardMultiple Choice

CKS Supply Chain Security Practice Question

An organization wants to implement supply chain security by signing all container images and verifying them before deployment. Which combination of tools is appropriate?

⚠ Common exam trap

The exam often tests the distinction between vulnerability scanning tools (Snyk, Trivy, Clair) and supply chain signing/verification tools (Cosign, Notary), leading candidates to confuse scanning for vulnerabilities with cryptographic signing and policy enforcement.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Cosign and Kyverno

Cosign is the tool for signing container images and storing signatures in an OCI-compliant registry, while Kyverno is a Kubernetes admission controller that can enforce policies to verify those signatures before allowing pod deployment. Together, they implement the full supply chain security workflow: signing images at build time and verifying them at deploy time via Kyverno's `verifyImages` rule.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Snyk and OPA

    Why it's wrong here

    Snyk scans dependencies and images for vulnerabilities, while OPA enforces policy at admission; neither signs images nor verifies signatures cryptographically. It is tempting because both are supply chain security tools, and OPA would correctly gate deployments on policy conditions rather than provenance.

  • ✓

    Cosign and Kyverno

    Why this is correct

    Cosign signs and verifies container image signatures using keyless or key-based attestations, while Kyverno's admission policies enforce that only signed images deploy. Together they satisfy the requirement to sign all images and verify them before deployment, blocking unsigned workloads at admission time.

  • ✗

    Trivy and Syft

    Why it's wrong here

    Trivy scans images for vulnerabilities and misconfigurations, and Syft generates SBOMs; neither creates or verifies cryptographic image signatures. It is tempting because both are supply chain security tools, and Syft would correctly produce an SBOM inventory for provenance tracking rather than signing.

  • ✗

    Clair and Notary

    Why it's wrong here

    Clair scans images for known vulnerabilities; Notary signs and verifies content, but Notary's TUF model targets arbitrary artefacts rather than Kubernetes admission-time image verification. It is tempting because both address supply chain concerns, and Notary would suit signing non-container artefacts in a registry.

Go deeper

Related to this question

About these practice questions

One of 845 original CKS practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.