CKS Supply Chain Security Practice Question
An organization wants to implement supply chain security by signing all container images and verifying them before deployment. Which combination of tools is appropriate?
⚠ Common exam trap
The exam often tests the distinction between vulnerability scanning tools (Snyk, Trivy, Clair) and supply chain signing/verification tools (Cosign, Notary), leading candidates to confuse scanning for vulnerabilities with cryptographic signing and policy enforcement.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Cosign and Kyverno
Cosign is the tool for signing container images and storing signatures in an OCI-compliant registry, while Kyverno is a Kubernetes admission controller that can enforce policies to verify those signatures before allowing pod deployment. Together, they implement the full supply chain security workflow: signing images at build time and verifying them at deploy time via Kyverno's `verifyImages` rule.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Snyk and OPA
Why it's wrong here
Snyk scans dependencies and images for vulnerabilities, while OPA enforces policy at admission; neither signs images nor verifies signatures cryptographically. It is tempting because both are supply chain security tools, and OPA would correctly gate deployments on policy conditions rather than provenance.
- ✓
Cosign and Kyverno
Why this is correct
Cosign signs and verifies container image signatures using keyless or key-based attestations, while Kyverno's admission policies enforce that only signed images deploy. Together they satisfy the requirement to sign all images and verify them before deployment, blocking unsigned workloads at admission time.
- ✗
Trivy and Syft
Why it's wrong here
Trivy scans images for vulnerabilities and misconfigurations, and Syft generates SBOMs; neither creates or verifies cryptographic image signatures. It is tempting because both are supply chain security tools, and Syft would correctly produce an SBOM inventory for provenance tracking rather than signing.
- ✗
Clair and Notary
Why it's wrong here
Clair scans images for known vulnerabilities; Notary signs and verifies content, but Notary's TUF model targets arbitrary artefacts rather than Kubernetes admission-time image verification. It is tempting because both address supply chain concerns, and Notary would suit signing non-container artefacts in a registry.
Go deeper
Related to this question
Learn chapter
Supply Chain Security: Container Image Security
Key term
Image Signing and Verification
Image signing and verification is the process of digitally signing a container image to prove its origin and integrity, and then checking that signature before using the image to ensure it was not tampered with.
Key term
OPA Gatekeeper
OPA Gatekeeper is a Kubernetes admission controller that enforces custom security and compliance policies on resources before they are created or updated in a cluster.
About these practice questions
One of 845 original CKS practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.