Courseiva
Supply Chain Security →hardMultiple Choice

CKS Supply Chain Security Practice Question

Developer A runs 'cosign verify --key cosign.pub myregistry/myimage:tag' and receives an error: 'No signatures found'. Developer B previously ran 'cosign sign --key cosign.key myregistry/myimage:tag'. What is the most likely cause of the verification failure?

⚠ Common exam trap

The CKS exam often tests the distinction between signature absence (no signatures found) and signature mismatch (invalid signature), where candidates mistakenly think a key mismatch would cause a 'no signatures' error instead of a validation failure.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The signing command failed to push the signature to the registry

The error 'No signatures found' indicates that the verification process could not locate any signature associated with the image in the registry. Since Developer B attempted to sign the image with 'cosign sign', the most likely cause is that the signing command failed to push the signature artifact (typically stored as a separate tag like 'myimage:sha256-<digest>.sig' in the same registry) to the registry. Without the signature being successfully uploaded, the 'cosign verify' command finds nothing to validate against the provided public key.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The image tag does not exist in the registry

    Why it's wrong here

    The 'No signatures found' error occurs only after cosign successfully retrieves the image manifest and computes its digest, then searches for a signature artifact tagged from that digest (e.g., 'sha256-<digest>.sig'). If the image tag itself does not exist, the registry returns a 404 MANIFEST_UNKNOWN error during manifest resolution, which happens before any signature lookup is attempted. Therefore, a non-existent tag yields a completely different failure message, not the signature-absence error, making this option incorrect.

  • ✓

    The signing command failed to push the signature to the registry

    Why this is correct

    Cosign signing computes a signature over the image digest and pushes it as a separate OCI artifact (typically under a tag like 'sha256-<digest>.sig') to the same registry. If the `cosign sign` command fails during that push—due to missing write permissions, expired credentials, or a network interruption—no signature object is persisted. When verification later queries the registry for that signature tag and finds nothing, it reports 'No signatures found', even though the image itself is perfectly valid. This directly matches the scenario, so it is the correct explanation.

  • ✗

    Developer B used a different private key to sign than the public key used for verification

    Why it's wrong here

    When a signature exists but was created using a different private key, the registry will contain a signature artifact, so cosign's discovery step will successfully list it. Only after retrieving the signature does cosign attempt cryptographic verification against the public key provided via `--key`; that step would fail with an 'invalid signature' or 'signature verification failed' error, not with 'No signatures found'. The 'No signatures found' message indicates that zero signature artifacts were discovered in the registry, meaning the failure occurs before key-based verification can even begin.

  • ✗

    Developer A used the public key instead of the private key

    Why it's wrong here

    Using a public key instead of the private key during signing would cause `cosign sign` itself to reject the operation, because generating a signature requires the private key component; the command would exit with a key-format or cipher error. Such a failure would either leave no signature pushed or produce a signing error that the developer would immediately observe, not a verification-time 'No signatures found'. The observed error is about the absence of signature artifacts in the registry, which is independent of whether the wrong key type was attempted at signing time.

About these practice questions

Courseiva writes every CKS question from scratch — 845 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on CKS

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. A CI pipeline fails with the error 'cosign: error: unable to verify image: no matching signatures' when running 'cosign verify --key pubkey.pem myregistry/myapp:latest'. The image was previously signed with a private key. What is the MOST likely cause?

hard
  • A.The public key is incorrect
  • B.The registry requires authentication
  • C.Cosign is not installed correctly
  • ✓ D.The image tag was overwritten without signing

Why D: If the image tag was overwritten (e.g., pushed again without signing), the old signatures are lost and the new image is unsigned.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.