CKS · domain
Supply Chain Security
Supply Chain Security covers hardening how images are built, stored, verified, and admitted into the cluster. Expect tasks on scanning images with Trivy, generating SBOMs, signing with Cosign, pinning images by digest, and enforcing policies via admission controllers like Kyverno or OPA Gatekeeper. Questions test both conceptual controls and hands-on YAML edits.
Focused practice
Practice Supply Chain Security questions
Scored sessions drawing only from this domain — pick a length below.
Start 20-question practice test →What this domain covers
What to know about Supply Chain Security
Be able to scan images, generate an SBOM, sign and verify with Cosign, and write an admission policy that blocks unsigned or untrusted-registry images. The most important thing: pin images by SHA digest and ensure your policy actually enforces it at admission time.
Scanning images for CVEs using Trivy and interpreting severity output
Generating and inspecting SBOMs with tools like Syft or Trivy
Enforcing image digest pinning and signature verification in Deployment YAML
Applying admission policies with Kyverno or OPA Gatekeeper to restrict registries
Watch out for
Common Supply Chain Security exam traps
- ▸Using mutable tags instead of SHA digests, which defeats integrity guarantees and fails policy checks
- ▸Confusing SBOM generation with vulnerability scanning; they are distinct artifacts and tools
- ▸Forgetting that admission controllers must be installed and webhook-configured before policies take effect
Question index
All Supply Chain Security questions (164)
Click any question to see the full explanation, or start a practice session above.
A developer wants to ensure that a pod always uses a specific version of an image that cannot be changed without updating the manifest. Which image reference should be used?
Medium2A security engineer needs to verify that a container image pulled from a private registry was signed by the organization's authorized build pipeline before allowing it to run in the cluster. The signatures are stored alongside the image in the OCI registry. Which command should the engineer use to perform this verification?
Medium3A developer wants to verify the signature of a container image before deploying it. Which command should they use along with Cosign?
Easy4You want to scan a container image for vulnerabilities before deploying it. Which command uses the Trivy tool to scan an image?
Easy5Which tool is used to generate an SBOM (Software Bill of Materials) for a container image?
Easy6Which TWO are best practices for Dockerfile security? (Select 2)
Medium7Which Kubernetes admission controller ensures that a pod only uses images from a specific registry?
Easy8Which tool can be used to perform static analysis of Kubernetes manifests for security issues?
Medium9A security team wants to ensure that all container images in a cluster are scanned for critical CVEs before they are run. They decide to use an admission controller. Which Kubernetes built-in admission controller should they configure?
Medium10Developer A runs 'cosign verify --key cosign.pub myregistry/myimage:tag' and receives an error: 'No signatures found'. Developer B previously ran 'cosign sign --key cosign.key myregistry/myimage:tag'. What is the most likely cause of the verification failure?
Hard11A developer wants to create a Deployment that runs as a non-root user. Which YAML snippet correctly sets the security context to run the container with UID 1000?
Medium12Which of the following is a static analysis tool for Kubernetes manifests that can be used to find misconfigurations?
Medium13What is the correct way to specify a container image using a SHA digest instead of a tag for immutable deployments?
Medium14What is the purpose of using a non-root user in a container image?
Easy15You are implementing supply chain security for container images. Which tool would you use to scan a local directory of Dockerfiles and Kubernetes manifests for known vulnerabilities?
Medium16Which Kyverno policy action is used to automatically mutate a resource to add a sidecar container for security?
Medium17A development team uses a custom container image for their application, built from a base image that includes multiple CVEs. The security team requires that no container runs with known critical vulnerabilities. Which approach best ensures that only images with no critical vulnerabilities are deployed in production?
Medium18Which THREE are valid methods to enforce that only images from a specific registry can be deployed in a Kubernetes cluster? (Select three.)
Hard19Which tool can generate an SBOM for a container image?
Medium20Which of the following is a BEST practice for securing container images in a Dockerfile?
Easy21Which command is used with Cosign to sign a container image?
Easy22An administrator runs 'kubectl describe pod secure-pod' and sees that the pod is in a Pending state with the event 'Error: ImagePullBackOff' and the message 'unauthorized: authentication required'. The image is stored in a private registry. What is the most likely cause?
Hard23A security policy requires that all container images must have a signed attestation. Which Cosign command would an admin add to the CI pipeline to create this attestation?
Medium24You need to enforce that all images deployed in the cluster are signed by a trusted key. Which Kubernetes admission control mechanism would you use?
Medium25A security admin runs 'trivy image --severity CRITICAL,HIGH myrepo/myapp:latest' and sees many CVEs. The admin wants to ensure that only images with no CRITICAL or HIGH severity vulnerabilities are deployed to the cluster. Which admission controller should be configured to enforce this policy?
Medium26An organization uses Kyverno to enforce policies. Which Kyverno rule action would you use to require that all images come from a specific registry?
Medium27A Kubernetes cluster uses the ImagePolicyWebhook admission controller to enforce image signature verification. The administrator notices that pods are being admitted even when the webhook backend is unreachable. The cluster is configured with defaultAllow: true in the admission configuration. What is the most likely cause of this behavior?
Hard28Which THREE of the following are best practices for securing the software supply chain in a CI/CD pipeline?
Medium29A DevOps team wants to enforce that all Deployments must have a specific label 'app.kubernetes.io/name'. Which tool can be used to validate this in the admission controller stage?
Hard30Which YAML field in a Deployment specifies the container user should not run as root?
Easy31A DevOps team uses a CI/CD pipeline to build container images and push them to a private registry. To minimize the risk of supply chain attacks, which of the following is the most effective security control to implement?
Easy32A CI/CD pipeline uses cosign attest to add an SBOM attestation to an image. Later, during deployment, which command verifies the attestation?
Hard33Which tool is used to generate a Software Bill of Materials (SBOM) for a container image?
Easy34A security engineer is using cosign to sign a container image. The engineer runs 'cosign sign --key cosign.key registry.example.com/app:1.0' and receives an error: 'Error: signing [registry.example.com/app:1.0]: getting signer: reading key: PEM decode failed: invalid pem block'. What is the most likely cause of this error?
Hard35A pod is stuck in Pending state. 'kubectl describe pod' shows '0/1 nodes are available: 1 node(s) had taint {node-role.kubernetes.io/control-plane: }, that the pod didn't tolerate.' The pod does not specify any tolerations. What is the most likely cause?
Hard36A cluster administrator wants to allow only images from a specific registry (e.g., 'myregistry.io') to be deployed in the cluster. Which tool can be used to enforce this via admission control?
Hard37A developer is building a container image and wants to ensure that the image is free from known vulnerabilities before pushing it to a registry. The developer decides to use Trivy. Which command should the developer run to scan the image for vulnerabilities?
Easy38Which TWO of the following are tools for image signing and verification? (Select TWO)
Medium39A DevOps engineer wants to ensure that a container image is signed and the signature is verified before deployment. Which Cosign command verifies an image signature?
Medium40Which THREE of the following are best practices for securing the software supply chain in Kubernetes?
Hard41Which of the following is a best practice for securing container images?
Medium42A cluster has the ImagePolicyWebhook admission controller enabled. A pod creation is denied with the message 'image policy check failed'. The webhook server returns an error. Which of the following could be a valid reason?
Hard43Which two of the following are best practices for container image security? (Select TWO.)
Medium44Which of the following is a best practice when writing a Dockerfile for a containerized application?
Easy45Which TWO practices improve supply chain security for container images? (Select two.)
Hard46An administrator wants to perform static analysis on Kubernetes manifest files to find security misconfigurations. Which tool is specifically designed for this?
Medium47Which of the following is a recommended Dockerfile best practice to improve container security?
Easy48A security engineer wants to enforce that all images in the cluster must come from a trusted registry 'trusted-registry.io'. They are using OPA/Gatekeeper. Which constraint template and constraint combination would achieve this?
Hard49A developer wants to sign a container image using Cosign. Which command should they run after building and pushing the image to a registry?
Easy50An administrator wants to ensure that only images from a specific registry (e.g., myregistry.internal) can run in the cluster. Which tool can be used to enforce this via admission control?
Medium51An admin wants to scan a local filesystem for vulnerabilities using Trivy. Which command should they use?
Medium52You need to ensure that all containers in your cluster run with a read-only root filesystem. Which field should be set in the container's security context?
Medium53You are a security engineer at a fintech startup. The company runs a Kubernetes cluster in production with hundreds of microservices. Recently, a container image from a public registry was compromised, and the attacker injected a backdoor that exfiltrated customer data. The CISO mandates that all images must come from an internal registry that only stores approved, scanned, and signed images. Currently, developers build images locally and push them to Docker Hub, then reference those images in Kubernetes manifests. You have deployed Harbor as a private registry with vulnerability scanning and Cosign for signing. However, you notice that some pods are still running images directly from Docker Hub. You need to enforce that only images from your internal Harbor registry can be used in the cluster. You cannot change the Kubernetes manifests immediately because of a large backlog. You have access to the cluster's kubelet configuration and can modify cluster-level components. Which single action will most effectively block any pod that tries to use an image not hosted on your internal registry?
Hard54A security team wants to automatically reject any Pod that uses an image tagged with 'latest'. Which tool can be used to define this policy at the admission level?
Medium55Which three of the following are valid ways to enforce supply chain security in a Kubernetes cluster? (Select THREE.)
Hard56Which THREE of the following are correct statements about Kubernetes admission controllers in the context of supply chain security? (Select 3)
Hard57You run 'trivy image myapp:latest' and the scan reports several critical CVEs. What is the best action to take?
Medium58An administrator runs 'trivy image myapp:1.0' and receives an output with several CRITICAL vulnerabilities. What is the best next step to ensure the image is secure before deployment?
Medium59A DevOps engineer wants to enforce that all container images running in the cluster are signed using Cosign. Which Kubernetes admission controller is designed for this purpose?
Medium60Which command would you use to sign a container image with Cosign?
Easy61Which THREE of the following can be used to enforce policies on container images in a Kubernetes cluster? (Select 3)
Hard62What is the purpose of an SBOM (Software Bill of Materials) in the context of supply chain security?
Medium63A security policy requires that all container images must be signed using Cosign. Which admission controller enforces signature verification at pod creation time?
Medium64You need to sign a container image using cosign with a key stored in an environment variable. Which command should you use?
Medium65What does SBOM stand for in the context of supply chain security?
Easy66An administrator wants to ensure that a Deployment uses a specific image digest (SHA256) instead of a tag. Which field in the Deployment YAML should be modified?
Medium67An organization wants to implement supply chain security by signing all container images and verifying them before deployment. Which combination of tools is appropriate?
Hard68Which static analysis tool is specifically designed to evaluate Kubernetes manifests against security best practices?
Medium69Which static analysis tool can be used to check Kubernetes manifests for security misconfigurations?
Easy70An organization uses a GitOps workflow with Argo CD to deploy applications to Kubernetes. The security team wants to ensure that container images are immutable and signed. They currently use a private container registry (Harbor) with vulnerability scanning and Cosign for signing. Which combination of controls best enforces that only signed and scanned images are deployed?
Hard71What is the primary purpose of an SBOM in supply chain security?
Easy72Which TWO of the following are valid ways to verify a container image signature using cosign?
Medium73Which TWO are benefits of using a distroless base image over a full OS image like Ubuntu? (Select two.)
Medium74A security policy requires that all container images use SHA-based digests instead of tags. Which approach ensures this in a Deployment YAML?
Medium75Which TWO of the following admission controllers are relevant for supply chain security in Kubernetes?
Hard76Match each Kubernetes API server flag to its security function.
Medium77Which THREE of the following are valid approaches to prevent containers from running as root in a Kubernetes cluster?
Hard78A user creates a Deployment with image 'alpine:3.18' and the Pod status is 'ErrImagePull'. The admin checks the image policy and sees that only images with SHA digests are allowed. What is the fix?
Hard79A cluster uses Kyverno to enforce that all images come from a trusted registry. A new Deployment fails with a message that the image 'docker.io/library/nginx:latest' is not allowed. What Kyverno policy rule likely caused this?
Hard80A pod is running in a namespace that has a Kyverno policy requiring all images to come from a trusted registry. The pod is using an image from an untrusted registry. What will happen when the pod is created?
Medium81A Kubernetes cluster has Kyverno installed. You want to enforce that all container images come from a trusted registry 'trusted-registry.example.com'. Which Kyverno policy rule type would you use?
Medium82A security engineer wants to ensure that only images signed with a specific key are allowed to run in the cluster. Which tool can be used to sign container images?
Easy83Which TWO tools can generate an SBOM for a container image? (Select two.)
Medium84You are auditing your cluster's supply chain security. You need to generate a Software Bill of Materials (SBOM) for a container image. Which tool should you use?
Hard85Which command is used to sign a container image with Cosign?
Easy86Which TWO of the following are tools that can be used to generate an SBOM for a container image?
Easy87A security engineer wants to integrate image scanning into a CI/CD pipeline. They are using a tool that can scan the filesystem of the build context before building the image. Which tool is best suited for this purpose?
Medium88Which TWO of the following are best practices for securing the software supply chain in a CI/CD pipeline?
Medium89Which of the following is a BEST practice for container images to reduce the attack surface?
Easy90Which TWO of the following are best practices for securing the container supply chain? (Select 2)
Medium91You are auditing a cluster's supply chain security. You find that many pods are running images from public registries without any pinning or verification. Which TWO actions would most effectively reduce the risk of pulling malicious images?
Easy92Which two of the following are best practices for securing a CI/CD pipeline that builds and deploys container images? (Select TWO.)
Medium93A security engineer wants to scan a container image for vulnerabilities using Trivy. Which command should they use?
Easy94A DevOps engineer is setting up a CI/CD pipeline to scan container images for vulnerabilities. They want to fail the pipeline if any critical vulnerabilities are found. Which command should they use to scan the image and produce a JSON output that can be parsed?
Medium95A security team is implementing supply chain security for their Kubernetes cluster. They want to ensure that only container images that have been signed and verified are deployed. They are evaluating admission controllers and tools. Which TWO of the following are valid approaches to enforce image signature verification at admission time? (Choose two.)
Medium96An OPA/Gatekeeper constraint is configured to allow only images from 'trusted-registry.io'. A pod is created with image 'trusted-registry.io/app:v1' but is denied. Which is the MOST likely cause?
Hard97Which THREE are valid methods to verify the integrity and origin of a container image? (Select 3)
Hard98Which of the following is a best practice for Dockerfiles to improve supply chain security?
Medium99To verify a signed container image, which command should be used?
Medium100Which TWO of the following are valid methods to ensure only signed images are deployed in a Kubernetes cluster?
Medium101In a CI/CD pipeline, at which stage should container image scanning be performed?
Medium102Which THREE of the following are valid flags for the 'trivy image' command to output results in different formats?
Easy103A security best practice for Dockerfiles is to avoid hardcoded secrets. Which Dockerfile instruction is MOST likely to contain a hardcoded secret?
Easy104A security audit reveals that a container image running in production contains a critical vulnerability (CVE-2024-1234). The image was built from a base image that had the vulnerability. What is the MOST effective long-term solution to prevent such issues?
Medium105Which TWO of the following are best practices for Dockerfile security according to CKS guidelines?
Medium106A security policy requires that all container images must reference a specific SHA256 digest instead of a tag. You need to enforce this using Kyverno. Which Kyverno rule type and pattern would you use?
Hard107An administrator runs 'trivy image --severity HIGH,CRITICAL myapp:v1.0' and sees no vulnerabilities. However, a security scan of the same image using a different tool reports several HIGH severity CVEs. What is the MOST likely reason for this discrepancy?
Medium108An admin runs 'kubectl run test-pod --image=nginx:latest' and the Pod is created but immediately enters 'CrashLoopBackOff'. 'kubectl describe pod test-pod' shows 'Back-off restarting failed container'. Which admission controller might cause this if misconfigured?
Hard109A developer creates a Dockerfile with 'FROM ubuntu:latest'. The security team recommends using a minimal base image. Which change minimizes the attack surface?
Hard110Which of the following is a static analysis tool for Kubernetes manifests?
Easy111You are configuring ImagePolicyWebhook admission controller to reject images not signed by a trusted authority. After deploying the webhook, you notice that pods are being rejected even for images that are properly signed. Which configuration change is MOST likely to fix this?
Hard112A pod is stuck in Pending state. 'kubectl describe pod' shows the event: '0/4 nodes are available: 1 node had taint {node-role.kubernetes.io/control-plane: }, that the pod didn't tolerate, 3 Insufficient memory.' The pod YAML does not specify any tolerations. Which command would allow the pod to schedule on the control-plane node?
Hard113A Kubernetes cluster has Kyverno installed. A policy requires that all images come from a trusted registry 'trusted.example.com'. A Deployment uses the image 'nginx:latest'. When the Deployment is created, it is blocked. What Kyverno policy action is being used?
Medium114A DevOps engineer runs 'trivy image myapp:latest' and finds a critical CVE in the base image. Which Dockerfile change would BEST address this?
Medium115A Kyverno policy is written to require all images to use SHA256 digests instead of tags. The policy uses a 'validate' rule with 'pattern' on 'spec.containers[*].image'. Which pattern would match an image reference like 'registry.example.com/myapp@sha256:abc123...'?
Hard116In a CI/CD pipeline, which step is MOST effective for detecting known vulnerabilities in a container image before deployment?
Easy117Which command scans a Docker image for CVEs using Trivy?
Easy118Which TWO of the following are valid methods to verify the integrity of a container image in a Kubernetes supply chain? (Select 2)
Medium119Which TWO of the following are valid admission controllers in Kubernetes? (Select TWO)
Medium120Refer to the exhibit. A cluster has the ClusterImagePolicy shown. A developer creates a pod with an image from registry.example.com/myapp:v1, which was built and signed by a GitHub Actions workflow that is NOT defined in the policy (different workflow). Which behavior will occur when the pod is created?
Hard121During a CI/CD pipeline, you run 'trivy image myapp:latest' and get a high number of vulnerabilities. What is the BEST action to reduce the vulnerability count?
Medium122A security engineer runs 'kubesec scan deployment.yaml' and receives a score of -1. What does this score indicate?
Medium123Which TWO of the following are valid methods to supply a Kubernetes manifest to kubesec for static analysis?
Medium124Which THREE of the following are best practices for writing Dockerfiles?
Easy125You are tasked with ensuring that all container images in your cluster are scanned for vulnerabilities before being deployed. You have set up Trivy in your CI/CD pipeline and want to enforce that only images with no critical vulnerabilities are allowed. Which admission controller should you configure to reject pods using non-compliant images?
Medium126A security engineer wants to ensure that all container images in a Kubernetes cluster have a non-root user. Which admission controller can enforce this requirement?
Hard127Which TWO of the following are benefits of using an SBOM (Software Bill of Materials) in supply chain security?
Medium128You have a Kyverno policy that validates image registries. The policy should allow only images from `myregistry.example.com`. Which Kyverno rule field should be used to check the image registry?
Hard129A security scan report shows that a container image has several high-severity CVEs. The team wants to implement automated scanning in CI/CD pipeline. Which tool would you recommend for scanning container images in a CI pipeline?
Medium130Which TWO of the following are valid methods to verify the integrity of a container image? (Select 2)
Medium131Which of the following is a best practice for securing container images in a CI/CD pipeline?
Easy132An administrator wants to enforce that only images signed by a trusted key can run in the cluster. They have configured cosign and want to use a Kubernetes admission controller. Which tool should they deploy?
Medium133An administrator wants to verify that an image was signed by a specific key before deploying. Which Cosign command should be used?
Medium134A DevOps team wants to ensure that only signed images from a trusted registry are deployed in the cluster. They plan to use a webhook to intercept pod creation. Which tool is best suited for this task?
Easy135Which tool is specifically designed to generate a Software Bill of Materials (SBOM) for container images?
Easy136You are the lead security engineer for a large financial institution. The organization runs a Kubernetes cluster with 500+ microservices. The supply chain security team has implemented the following measures: (1) All images are built from a minimal base image (distroless) and scanned with Trivy before being pushed to a private registry. (2) Images are signed using cosign with a key stored in a hardware security module (HSM). (3) Kyverno policies enforce that only signed images from the private registry can run, and also enforce that containers run as non-root. (4) A binary authorization (binauthz) style admission controller verifies attestations. Recently, a critical vulnerability (CVE-2024-0001) was discovered in a popular open-source library used by several microservices. The library is included as a dependency in the base image. The vulnerability is remotely exploitable and has a CVSS score of 9.8. The security team needs to remediate this quickly. They have already patched the library and updated the base image. What is the BEST course of action to ensure all running pods use the new image?
Hard137A developer runs 'trivy image myapp:latest' and gets a report with several CRITICAL CVEs. Which action would BEST address the supply chain security risk?
Easy138A security engineer is configuring a Kubernetes cluster to enforce that all container images are signed by a trusted key before deployment. They deploy the Cosign admission controller and configure it with a public key. However, they notice that some pods are still being admitted with unsigned images. What is the most likely cause?
Hard139An administrator wants to ensure that only signed container images are deployed in the cluster. Which admission controller can be used to enforce this policy?
Medium140A CI pipeline fails with the error 'cosign: error: unable to verify image: no matching signatures' when running 'cosign verify --key pubkey.pem myregistry/myapp:latest'. The image was previously signed with a private key. What is the MOST likely cause?
Hard141Which command is used to sign a container image with Cosign and store the signature in an OCI registry?
Medium142A security admin wants to ensure that only images signed with a specific key can run in the cluster. Which admission controller should be enabled?
Medium143A security engineer needs to verify that a container image stored in a private OCI registry has not been tampered with before allowing it to run in a production cluster. The image was signed using Cosign with a key pair. The engineer has the public key. Which command should the engineer use to verify the signature?
Medium144Which of the following is a best practice for securing a Dockerfile?
Easy145Which TWO are recommended practices for securing a CI/CD pipeline that builds container images? (Select two.)
Medium146Which of the following is a best practice for securing container images in a Kubernetes environment?
Easy147An administrator wants to ensure that only images from a trusted registry 'myregistry.io' can run in the cluster. Which admission controller should be configured?
Medium148A CI/CD pipeline builds a Docker image and pushes it to a registry. To ensure supply chain security, the pipeline should scan the image for vulnerabilities before deployment. Which of the following is the correct command to scan a local Docker image using Trivy?
Medium149Which tool is commonly used to generate a Software Bill of Materials (SBOM) for a container image?
Easy150A security admin wants to ensure that all container images in a Kubernetes cluster are scanned for known vulnerabilities before being deployed. Which tool can be integrated into a CI/CD pipeline to scan container images for CVEs?
Medium151You want to allow only images from a specific registry (e.g., myregistry.io) to be deployed in your cluster. Which tool or approach is best suited for this requirement?
Hard152An organization uses a private container registry and wants to ensure that only images built from a specific CI/CD pipeline are deployed. Which combination of measures provides the strongest guarantee?
Hard153Which TWO of the following are valid methods to verify the integrity of a container image before deployment?
Medium154Which of the following is a static analysis tool for Kubernetes manifests that can identify security misconfigurations?
Easy155You are tasked with creating a Kubernetes admission controller that validates image signatures before allowing pods to run. Which admission controller should you configure?
Hard156Which TWO of the following tools can be used to generate or analyze SBOMs? (Select 2)
Medium157A security audit reveals that a Deployment uses an image with a mutable tag 'app:latest'. Which change ensures the image is immutable and traceable?
Hard158Arrange the steps to secure etcd in a Kubernetes cluster.
Medium159Which TWO of the following are best practices for securing the container supply chain?
Medium160A developer wants to ensure the container image used in a Deployment is immutable. Which approach BEST guarantees that the exact same image is used every time, preventing tag mutation?
Hard161A security team wants to ensure that only container images from a trusted registry (mytrustedregistry.io) are deployed in the cluster. They plan to use OPA/Gatekeeper. Which kind of Gatekeeper constraint template and constraint should they create?
Medium162A Kubernetes cluster enforces image signature verification using the Cosign admission controller. A developer attempts to deploy a pod using an image that was signed with a key that is not in the trusted public key list. The pod is rejected. Which component is responsible for this rejection?
Hard163You have configured Kyverno to enforce that all Pods must have an image from a trusted registry. However, a newly created Pod is not being rejected even though it uses an untrusted image. What is the most likely reason?
Hard164An admin runs 'kubectl run nginx --image=nginx' and the pod fails with 'ImagePullBackOff'. The cluster has an OPA/Gatekeeper constraint that only allows images from 'myregistry.io'. How can the admin quickly test the restriction?
MediumOther domains
All CKS exam domains
Frequently asked questions
- What does the Supply Chain Security domain cover on the CKS exam?
- Be able to scan images, generate an SBOM, sign and verify with Cosign, and write an admission policy that blocks unsigned or untrusted-registry images. The most important thing: pin images by SHA digest and ensure your policy actually enforces it at admission time.
- How many questions are in this domain?
- This page lists all 164 Supply Chain Security questions in the CKS question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
- What is the best way to practise this domain?
- Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
- Can I practise only Supply Chain Security questions?
- Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.