Courseiva

CKS · domain

Supply Chain Security

Supply Chain Security covers hardening how images are built, stored, verified, and admitted into the cluster. Expect tasks on scanning images with Trivy, generating SBOMs, signing with Cosign, pinning images by digest, and enforcing policies via admission controllers like Kyverno or OPA Gatekeeper. Questions test both conceptual controls and hands-on YAML edits.

164 questions38 easy81 medium45 hard

Focused practice

Practice Supply Chain Security questions

Scored sessions drawing only from this domain — pick a length below.

Start 20-question practice test →

What this domain covers

What to know about Supply Chain Security

Be able to scan images, generate an SBOM, sign and verify with Cosign, and write an admission policy that blocks unsigned or untrusted-registry images. The most important thing: pin images by SHA digest and ensure your policy actually enforces it at admission time.

Scanning images for CVEs using Trivy and interpreting severity output

Generating and inspecting SBOMs with tools like Syft or Trivy

Enforcing image digest pinning and signature verification in Deployment YAML

Applying admission policies with Kyverno or OPA Gatekeeper to restrict registries

Watch out for

Common Supply Chain Security exam traps

  • ▸Using mutable tags instead of SHA digests, which defeats integrity guarantees and fails policy checks
  • ▸Confusing SBOM generation with vulnerability scanning; they are distinct artifacts and tools
  • ▸Forgetting that admission controllers must be installed and webhook-configured before policies take effect

Question index

All Supply Chain Security questions (164)

Click any question to see the full explanation, or start a practice session above.

1

A developer wants to ensure that a pod always uses a specific version of an image that cannot be changed without updating the manifest. Which image reference should be used?

Medium
2

A security engineer needs to verify that a container image pulled from a private registry was signed by the organization's authorized build pipeline before allowing it to run in the cluster. The signatures are stored alongside the image in the OCI registry. Which command should the engineer use to perform this verification?

Medium
3

A developer wants to verify the signature of a container image before deploying it. Which command should they use along with Cosign?

Easy
4

You want to scan a container image for vulnerabilities before deploying it. Which command uses the Trivy tool to scan an image?

Easy
5

Which tool is used to generate an SBOM (Software Bill of Materials) for a container image?

Easy
6

Which TWO are best practices for Dockerfile security? (Select 2)

Medium
7

Which Kubernetes admission controller ensures that a pod only uses images from a specific registry?

Easy
8

Which tool can be used to perform static analysis of Kubernetes manifests for security issues?

Medium
9

A security team wants to ensure that all container images in a cluster are scanned for critical CVEs before they are run. They decide to use an admission controller. Which Kubernetes built-in admission controller should they configure?

Medium
10

Developer A runs 'cosign verify --key cosign.pub myregistry/myimage:tag' and receives an error: 'No signatures found'. Developer B previously ran 'cosign sign --key cosign.key myregistry/myimage:tag'. What is the most likely cause of the verification failure?

Hard
11

A developer wants to create a Deployment that runs as a non-root user. Which YAML snippet correctly sets the security context to run the container with UID 1000?

Medium
12

Which of the following is a static analysis tool for Kubernetes manifests that can be used to find misconfigurations?

Medium
13

What is the correct way to specify a container image using a SHA digest instead of a tag for immutable deployments?

Medium
14

What is the purpose of using a non-root user in a container image?

Easy
15

You are implementing supply chain security for container images. Which tool would you use to scan a local directory of Dockerfiles and Kubernetes manifests for known vulnerabilities?

Medium
16

Which Kyverno policy action is used to automatically mutate a resource to add a sidecar container for security?

Medium
17

A development team uses a custom container image for their application, built from a base image that includes multiple CVEs. The security team requires that no container runs with known critical vulnerabilities. Which approach best ensures that only images with no critical vulnerabilities are deployed in production?

Medium
18

Which THREE are valid methods to enforce that only images from a specific registry can be deployed in a Kubernetes cluster? (Select three.)

Hard
19

Which tool can generate an SBOM for a container image?

Medium
20

Which of the following is a BEST practice for securing container images in a Dockerfile?

Easy
21

Which command is used with Cosign to sign a container image?

Easy
22

An administrator runs 'kubectl describe pod secure-pod' and sees that the pod is in a Pending state with the event 'Error: ImagePullBackOff' and the message 'unauthorized: authentication required'. The image is stored in a private registry. What is the most likely cause?

Hard
23

A security policy requires that all container images must have a signed attestation. Which Cosign command would an admin add to the CI pipeline to create this attestation?

Medium
24

You need to enforce that all images deployed in the cluster are signed by a trusted key. Which Kubernetes admission control mechanism would you use?

Medium
25

A security admin runs 'trivy image --severity CRITICAL,HIGH myrepo/myapp:latest' and sees many CVEs. The admin wants to ensure that only images with no CRITICAL or HIGH severity vulnerabilities are deployed to the cluster. Which admission controller should be configured to enforce this policy?

Medium
26

An organization uses Kyverno to enforce policies. Which Kyverno rule action would you use to require that all images come from a specific registry?

Medium
27

A Kubernetes cluster uses the ImagePolicyWebhook admission controller to enforce image signature verification. The administrator notices that pods are being admitted even when the webhook backend is unreachable. The cluster is configured with defaultAllow: true in the admission configuration. What is the most likely cause of this behavior?

Hard
28

Which THREE of the following are best practices for securing the software supply chain in a CI/CD pipeline?

Medium
29

A DevOps team wants to enforce that all Deployments must have a specific label 'app.kubernetes.io/name'. Which tool can be used to validate this in the admission controller stage?

Hard
30

Which YAML field in a Deployment specifies the container user should not run as root?

Easy
31

A DevOps team uses a CI/CD pipeline to build container images and push them to a private registry. To minimize the risk of supply chain attacks, which of the following is the most effective security control to implement?

Easy
32

A CI/CD pipeline uses cosign attest to add an SBOM attestation to an image. Later, during deployment, which command verifies the attestation?

Hard
33

Which tool is used to generate a Software Bill of Materials (SBOM) for a container image?

Easy
34

A security engineer is using cosign to sign a container image. The engineer runs 'cosign sign --key cosign.key registry.example.com/app:1.0' and receives an error: 'Error: signing [registry.example.com/app:1.0]: getting signer: reading key: PEM decode failed: invalid pem block'. What is the most likely cause of this error?

Hard
35

A pod is stuck in Pending state. 'kubectl describe pod' shows '0/1 nodes are available: 1 node(s) had taint {node-role.kubernetes.io/control-plane: }, that the pod didn't tolerate.' The pod does not specify any tolerations. What is the most likely cause?

Hard
36

A cluster administrator wants to allow only images from a specific registry (e.g., 'myregistry.io') to be deployed in the cluster. Which tool can be used to enforce this via admission control?

Hard
37

A developer is building a container image and wants to ensure that the image is free from known vulnerabilities before pushing it to a registry. The developer decides to use Trivy. Which command should the developer run to scan the image for vulnerabilities?

Easy
38

Which TWO of the following are tools for image signing and verification? (Select TWO)

Medium
39

A DevOps engineer wants to ensure that a container image is signed and the signature is verified before deployment. Which Cosign command verifies an image signature?

Medium
40

Which THREE of the following are best practices for securing the software supply chain in Kubernetes?

Hard
41

Which of the following is a best practice for securing container images?

Medium
42

A cluster has the ImagePolicyWebhook admission controller enabled. A pod creation is denied with the message 'image policy check failed'. The webhook server returns an error. Which of the following could be a valid reason?

Hard
43

Which two of the following are best practices for container image security? (Select TWO.)

Medium
44

Which of the following is a best practice when writing a Dockerfile for a containerized application?

Easy
45

Which TWO practices improve supply chain security for container images? (Select two.)

Hard
46

An administrator wants to perform static analysis on Kubernetes manifest files to find security misconfigurations. Which tool is specifically designed for this?

Medium
47

Which of the following is a recommended Dockerfile best practice to improve container security?

Easy
48

A security engineer wants to enforce that all images in the cluster must come from a trusted registry 'trusted-registry.io'. They are using OPA/Gatekeeper. Which constraint template and constraint combination would achieve this?

Hard
49

A developer wants to sign a container image using Cosign. Which command should they run after building and pushing the image to a registry?

Easy
50

An administrator wants to ensure that only images from a specific registry (e.g., myregistry.internal) can run in the cluster. Which tool can be used to enforce this via admission control?

Medium
51

An admin wants to scan a local filesystem for vulnerabilities using Trivy. Which command should they use?

Medium
52

You need to ensure that all containers in your cluster run with a read-only root filesystem. Which field should be set in the container's security context?

Medium
53

You are a security engineer at a fintech startup. The company runs a Kubernetes cluster in production with hundreds of microservices. Recently, a container image from a public registry was compromised, and the attacker injected a backdoor that exfiltrated customer data. The CISO mandates that all images must come from an internal registry that only stores approved, scanned, and signed images. Currently, developers build images locally and push them to Docker Hub, then reference those images in Kubernetes manifests. You have deployed Harbor as a private registry with vulnerability scanning and Cosign for signing. However, you notice that some pods are still running images directly from Docker Hub. You need to enforce that only images from your internal Harbor registry can be used in the cluster. You cannot change the Kubernetes manifests immediately because of a large backlog. You have access to the cluster's kubelet configuration and can modify cluster-level components. Which single action will most effectively block any pod that tries to use an image not hosted on your internal registry?

Hard
54

A security team wants to automatically reject any Pod that uses an image tagged with 'latest'. Which tool can be used to define this policy at the admission level?

Medium
55

Which three of the following are valid ways to enforce supply chain security in a Kubernetes cluster? (Select THREE.)

Hard
56

Which THREE of the following are correct statements about Kubernetes admission controllers in the context of supply chain security? (Select 3)

Hard
57

You run 'trivy image myapp:latest' and the scan reports several critical CVEs. What is the best action to take?

Medium
58

An administrator runs 'trivy image myapp:1.0' and receives an output with several CRITICAL vulnerabilities. What is the best next step to ensure the image is secure before deployment?

Medium
59

A DevOps engineer wants to enforce that all container images running in the cluster are signed using Cosign. Which Kubernetes admission controller is designed for this purpose?

Medium
60

Which command would you use to sign a container image with Cosign?

Easy
61

Which THREE of the following can be used to enforce policies on container images in a Kubernetes cluster? (Select 3)

Hard
62

What is the purpose of an SBOM (Software Bill of Materials) in the context of supply chain security?

Medium
63

A security policy requires that all container images must be signed using Cosign. Which admission controller enforces signature verification at pod creation time?

Medium
64

You need to sign a container image using cosign with a key stored in an environment variable. Which command should you use?

Medium
65

What does SBOM stand for in the context of supply chain security?

Easy
66

An administrator wants to ensure that a Deployment uses a specific image digest (SHA256) instead of a tag. Which field in the Deployment YAML should be modified?

Medium
67

An organization wants to implement supply chain security by signing all container images and verifying them before deployment. Which combination of tools is appropriate?

Hard
68

Which static analysis tool is specifically designed to evaluate Kubernetes manifests against security best practices?

Medium
69

Which static analysis tool can be used to check Kubernetes manifests for security misconfigurations?

Easy
70

An organization uses a GitOps workflow with Argo CD to deploy applications to Kubernetes. The security team wants to ensure that container images are immutable and signed. They currently use a private container registry (Harbor) with vulnerability scanning and Cosign for signing. Which combination of controls best enforces that only signed and scanned images are deployed?

Hard
71

What is the primary purpose of an SBOM in supply chain security?

Easy
72

Which TWO of the following are valid ways to verify a container image signature using cosign?

Medium
73

Which TWO are benefits of using a distroless base image over a full OS image like Ubuntu? (Select two.)

Medium
74

A security policy requires that all container images use SHA-based digests instead of tags. Which approach ensures this in a Deployment YAML?

Medium
75

Which TWO of the following admission controllers are relevant for supply chain security in Kubernetes?

Hard
76

Match each Kubernetes API server flag to its security function.

Medium
77

Which THREE of the following are valid approaches to prevent containers from running as root in a Kubernetes cluster?

Hard
78

A user creates a Deployment with image 'alpine:3.18' and the Pod status is 'ErrImagePull'. The admin checks the image policy and sees that only images with SHA digests are allowed. What is the fix?

Hard
79

A cluster uses Kyverno to enforce that all images come from a trusted registry. A new Deployment fails with a message that the image 'docker.io/library/nginx:latest' is not allowed. What Kyverno policy rule likely caused this?

Hard
80

A pod is running in a namespace that has a Kyverno policy requiring all images to come from a trusted registry. The pod is using an image from an untrusted registry. What will happen when the pod is created?

Medium
81

A Kubernetes cluster has Kyverno installed. You want to enforce that all container images come from a trusted registry 'trusted-registry.example.com'. Which Kyverno policy rule type would you use?

Medium
82

A security engineer wants to ensure that only images signed with a specific key are allowed to run in the cluster. Which tool can be used to sign container images?

Easy
83

Which TWO tools can generate an SBOM for a container image? (Select two.)

Medium
84

You are auditing your cluster's supply chain security. You need to generate a Software Bill of Materials (SBOM) for a container image. Which tool should you use?

Hard
85

Which command is used to sign a container image with Cosign?

Easy
86

Which TWO of the following are tools that can be used to generate an SBOM for a container image?

Easy
87

A security engineer wants to integrate image scanning into a CI/CD pipeline. They are using a tool that can scan the filesystem of the build context before building the image. Which tool is best suited for this purpose?

Medium
88

Which TWO of the following are best practices for securing the software supply chain in a CI/CD pipeline?

Medium
89

Which of the following is a BEST practice for container images to reduce the attack surface?

Easy
90

Which TWO of the following are best practices for securing the container supply chain? (Select 2)

Medium
91

You are auditing a cluster's supply chain security. You find that many pods are running images from public registries without any pinning or verification. Which TWO actions would most effectively reduce the risk of pulling malicious images?

Easy
92

Which two of the following are best practices for securing a CI/CD pipeline that builds and deploys container images? (Select TWO.)

Medium
93

A security engineer wants to scan a container image for vulnerabilities using Trivy. Which command should they use?

Easy
94

A DevOps engineer is setting up a CI/CD pipeline to scan container images for vulnerabilities. They want to fail the pipeline if any critical vulnerabilities are found. Which command should they use to scan the image and produce a JSON output that can be parsed?

Medium
95

A security team is implementing supply chain security for their Kubernetes cluster. They want to ensure that only container images that have been signed and verified are deployed. They are evaluating admission controllers and tools. Which TWO of the following are valid approaches to enforce image signature verification at admission time? (Choose two.)

Medium
96

An OPA/Gatekeeper constraint is configured to allow only images from 'trusted-registry.io'. A pod is created with image 'trusted-registry.io/app:v1' but is denied. Which is the MOST likely cause?

Hard
97

Which THREE are valid methods to verify the integrity and origin of a container image? (Select 3)

Hard
98

Which of the following is a best practice for Dockerfiles to improve supply chain security?

Medium
99

To verify a signed container image, which command should be used?

Medium
100

Which TWO of the following are valid methods to ensure only signed images are deployed in a Kubernetes cluster?

Medium
101

In a CI/CD pipeline, at which stage should container image scanning be performed?

Medium
102

Which THREE of the following are valid flags for the 'trivy image' command to output results in different formats?

Easy
103

A security best practice for Dockerfiles is to avoid hardcoded secrets. Which Dockerfile instruction is MOST likely to contain a hardcoded secret?

Easy
104

A security audit reveals that a container image running in production contains a critical vulnerability (CVE-2024-1234). The image was built from a base image that had the vulnerability. What is the MOST effective long-term solution to prevent such issues?

Medium
105

Which TWO of the following are best practices for Dockerfile security according to CKS guidelines?

Medium
106

A security policy requires that all container images must reference a specific SHA256 digest instead of a tag. You need to enforce this using Kyverno. Which Kyverno rule type and pattern would you use?

Hard
107

An administrator runs 'trivy image --severity HIGH,CRITICAL myapp:v1.0' and sees no vulnerabilities. However, a security scan of the same image using a different tool reports several HIGH severity CVEs. What is the MOST likely reason for this discrepancy?

Medium
108

An admin runs 'kubectl run test-pod --image=nginx:latest' and the Pod is created but immediately enters 'CrashLoopBackOff'. 'kubectl describe pod test-pod' shows 'Back-off restarting failed container'. Which admission controller might cause this if misconfigured?

Hard
109

A developer creates a Dockerfile with 'FROM ubuntu:latest'. The security team recommends using a minimal base image. Which change minimizes the attack surface?

Hard
110

Which of the following is a static analysis tool for Kubernetes manifests?

Easy
111

You are configuring ImagePolicyWebhook admission controller to reject images not signed by a trusted authority. After deploying the webhook, you notice that pods are being rejected even for images that are properly signed. Which configuration change is MOST likely to fix this?

Hard
112

A pod is stuck in Pending state. 'kubectl describe pod' shows the event: '0/4 nodes are available: 1 node had taint {node-role.kubernetes.io/control-plane: }, that the pod didn't tolerate, 3 Insufficient memory.' The pod YAML does not specify any tolerations. Which command would allow the pod to schedule on the control-plane node?

Hard
113

A Kubernetes cluster has Kyverno installed. A policy requires that all images come from a trusted registry 'trusted.example.com'. A Deployment uses the image 'nginx:latest'. When the Deployment is created, it is blocked. What Kyverno policy action is being used?

Medium
114

A DevOps engineer runs 'trivy image myapp:latest' and finds a critical CVE in the base image. Which Dockerfile change would BEST address this?

Medium
115

A Kyverno policy is written to require all images to use SHA256 digests instead of tags. The policy uses a 'validate' rule with 'pattern' on 'spec.containers[*].image'. Which pattern would match an image reference like 'registry.example.com/myapp@sha256:abc123...'?

Hard
116

In a CI/CD pipeline, which step is MOST effective for detecting known vulnerabilities in a container image before deployment?

Easy
117

Which command scans a Docker image for CVEs using Trivy?

Easy
118

Which TWO of the following are valid methods to verify the integrity of a container image in a Kubernetes supply chain? (Select 2)

Medium
119

Which TWO of the following are valid admission controllers in Kubernetes? (Select TWO)

Medium
120

Refer to the exhibit. A cluster has the ClusterImagePolicy shown. A developer creates a pod with an image from registry.example.com/myapp:v1, which was built and signed by a GitHub Actions workflow that is NOT defined in the policy (different workflow). Which behavior will occur when the pod is created?

Hard
121

During a CI/CD pipeline, you run 'trivy image myapp:latest' and get a high number of vulnerabilities. What is the BEST action to reduce the vulnerability count?

Medium
122

A security engineer runs 'kubesec scan deployment.yaml' and receives a score of -1. What does this score indicate?

Medium
123

Which TWO of the following are valid methods to supply a Kubernetes manifest to kubesec for static analysis?

Medium
124

Which THREE of the following are best practices for writing Dockerfiles?

Easy
125

You are tasked with ensuring that all container images in your cluster are scanned for vulnerabilities before being deployed. You have set up Trivy in your CI/CD pipeline and want to enforce that only images with no critical vulnerabilities are allowed. Which admission controller should you configure to reject pods using non-compliant images?

Medium
126

A security engineer wants to ensure that all container images in a Kubernetes cluster have a non-root user. Which admission controller can enforce this requirement?

Hard
127

Which TWO of the following are benefits of using an SBOM (Software Bill of Materials) in supply chain security?

Medium
128

You have a Kyverno policy that validates image registries. The policy should allow only images from `myregistry.example.com`. Which Kyverno rule field should be used to check the image registry?

Hard
129

A security scan report shows that a container image has several high-severity CVEs. The team wants to implement automated scanning in CI/CD pipeline. Which tool would you recommend for scanning container images in a CI pipeline?

Medium
130

Which TWO of the following are valid methods to verify the integrity of a container image? (Select 2)

Medium
131

Which of the following is a best practice for securing container images in a CI/CD pipeline?

Easy
132

An administrator wants to enforce that only images signed by a trusted key can run in the cluster. They have configured cosign and want to use a Kubernetes admission controller. Which tool should they deploy?

Medium
133

An administrator wants to verify that an image was signed by a specific key before deploying. Which Cosign command should be used?

Medium
134

A DevOps team wants to ensure that only signed images from a trusted registry are deployed in the cluster. They plan to use a webhook to intercept pod creation. Which tool is best suited for this task?

Easy
135

Which tool is specifically designed to generate a Software Bill of Materials (SBOM) for container images?

Easy
136

You are the lead security engineer for a large financial institution. The organization runs a Kubernetes cluster with 500+ microservices. The supply chain security team has implemented the following measures: (1) All images are built from a minimal base image (distroless) and scanned with Trivy before being pushed to a private registry. (2) Images are signed using cosign with a key stored in a hardware security module (HSM). (3) Kyverno policies enforce that only signed images from the private registry can run, and also enforce that containers run as non-root. (4) A binary authorization (binauthz) style admission controller verifies attestations. Recently, a critical vulnerability (CVE-2024-0001) was discovered in a popular open-source library used by several microservices. The library is included as a dependency in the base image. The vulnerability is remotely exploitable and has a CVSS score of 9.8. The security team needs to remediate this quickly. They have already patched the library and updated the base image. What is the BEST course of action to ensure all running pods use the new image?

Hard
137

A developer runs 'trivy image myapp:latest' and gets a report with several CRITICAL CVEs. Which action would BEST address the supply chain security risk?

Easy
138

A security engineer is configuring a Kubernetes cluster to enforce that all container images are signed by a trusted key before deployment. They deploy the Cosign admission controller and configure it with a public key. However, they notice that some pods are still being admitted with unsigned images. What is the most likely cause?

Hard
139

An administrator wants to ensure that only signed container images are deployed in the cluster. Which admission controller can be used to enforce this policy?

Medium
140

A CI pipeline fails with the error 'cosign: error: unable to verify image: no matching signatures' when running 'cosign verify --key pubkey.pem myregistry/myapp:latest'. The image was previously signed with a private key. What is the MOST likely cause?

Hard
141

Which command is used to sign a container image with Cosign and store the signature in an OCI registry?

Medium
142

A security admin wants to ensure that only images signed with a specific key can run in the cluster. Which admission controller should be enabled?

Medium
143

A security engineer needs to verify that a container image stored in a private OCI registry has not been tampered with before allowing it to run in a production cluster. The image was signed using Cosign with a key pair. The engineer has the public key. Which command should the engineer use to verify the signature?

Medium
144

Which of the following is a best practice for securing a Dockerfile?

Easy
145

Which TWO are recommended practices for securing a CI/CD pipeline that builds container images? (Select two.)

Medium
146

Which of the following is a best practice for securing container images in a Kubernetes environment?

Easy
147

An administrator wants to ensure that only images from a trusted registry 'myregistry.io' can run in the cluster. Which admission controller should be configured?

Medium
148

A CI/CD pipeline builds a Docker image and pushes it to a registry. To ensure supply chain security, the pipeline should scan the image for vulnerabilities before deployment. Which of the following is the correct command to scan a local Docker image using Trivy?

Medium
149

Which tool is commonly used to generate a Software Bill of Materials (SBOM) for a container image?

Easy
150

A security admin wants to ensure that all container images in a Kubernetes cluster are scanned for known vulnerabilities before being deployed. Which tool can be integrated into a CI/CD pipeline to scan container images for CVEs?

Medium
151

You want to allow only images from a specific registry (e.g., myregistry.io) to be deployed in your cluster. Which tool or approach is best suited for this requirement?

Hard
152

An organization uses a private container registry and wants to ensure that only images built from a specific CI/CD pipeline are deployed. Which combination of measures provides the strongest guarantee?

Hard
153

Which TWO of the following are valid methods to verify the integrity of a container image before deployment?

Medium
154

Which of the following is a static analysis tool for Kubernetes manifests that can identify security misconfigurations?

Easy
155

You are tasked with creating a Kubernetes admission controller that validates image signatures before allowing pods to run. Which admission controller should you configure?

Hard
156

Which TWO of the following tools can be used to generate or analyze SBOMs? (Select 2)

Medium
157

A security audit reveals that a Deployment uses an image with a mutable tag 'app:latest'. Which change ensures the image is immutable and traceable?

Hard
158

Arrange the steps to secure etcd in a Kubernetes cluster.

Medium
159

Which TWO of the following are best practices for securing the container supply chain?

Medium
160

A developer wants to ensure the container image used in a Deployment is immutable. Which approach BEST guarantees that the exact same image is used every time, preventing tag mutation?

Hard
161

A security team wants to ensure that only container images from a trusted registry (mytrustedregistry.io) are deployed in the cluster. They plan to use OPA/Gatekeeper. Which kind of Gatekeeper constraint template and constraint should they create?

Medium
162

A Kubernetes cluster enforces image signature verification using the Cosign admission controller. A developer attempts to deploy a pod using an image that was signed with a key that is not in the trusted public key list. The pod is rejected. Which component is responsible for this rejection?

Hard
163

You have configured Kyverno to enforce that all Pods must have an image from a trusted registry. However, a newly created Pod is not being rejected even though it uses an untrusted image. What is the most likely reason?

Hard
164

An admin runs 'kubectl run nginx --image=nginx' and the pod fails with 'ImagePullBackOff'. The cluster has an OPA/Gatekeeper constraint that only allows images from 'myregistry.io'. How can the admin quickly test the restriction?

Medium

Frequently asked questions

What does the Supply Chain Security domain cover on the CKS exam?
Be able to scan images, generate an SBOM, sign and verify with Cosign, and write an admission policy that blocks unsigned or untrusted-registry images. The most important thing: pin images by SHA digest and ensure your policy actually enforces it at admission time.
How many questions are in this domain?
This page lists all 164 Supply Chain Security questions in the CKS question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
What is the best way to practise this domain?
Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
Can I practise only Supply Chain Security questions?
Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.
cncf-cks CNCF-CKS cks supply chain Practice Questions