CKS Supply Chain Security Practice Question
In a CI/CD pipeline, at which stage should container image scanning be performed?
⚠ Common exam trap
The CKS exam tests the concept of 'shift left' in security, and the trap here is that candidates may think scanning before code commit (Option C) is valid, but container images are not built until after the commit, so scanning must occur on the built image artifact.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
After building the image but before pushing to registry
Container image scanning should be performed after building the image but before pushing it to the registry (Option D). This ensures that vulnerabilities are detected before the image is stored and distributed, preventing insecure images from being deployed. Scanning at this stage integrates security into the CI/CD pipeline, allowing teams to fail the build or trigger remediation before the image reaches production.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Only when a vulnerability is reported
Why it's wrong here
Waiting for a vulnerability report before scanning is a reactive approach, but container images accumulate CVEs continuously after publication. By the time an external report surfaces, the vulnerable image may already be running in production or be deeply embedded in the supply chain. Proactive scanning, integrated into the pipeline, creates a baseline that lets you measure new risks against known-good states and remediate before exploitation.
- ✗
After deployment to production
Why it's wrong here
Scanning after deployment to production defeats the entire purpose of a security gate: it allows vulnerable images to be stored in the registry and executed on live clusters, exposing real workloads to known exploits. At that point, remediation demands emergency rollbacks or hotfixes, which are costly and slow. The registry scan is meant to prevent vulnerable images from ever entering the distribution chain, not to discover them after the fact.
- ✗
Before code commit
Why it's wrong here
Before a code commit, there is no container image to scan—only source files and build context exist on the developer's machine. Container image scanning examines the built filesystem, OS package metadata, and dependency artifacts that are materialized only after the build process runs. Traditional SAST or source-code analysis can be performed pre-commit, but image vulnerability scanning is fundamentally impossible at that stage because the image's layers do not yet exist.
- ✓
After building the image but before pushing to registry
Why this is correct
Scanning after the image is built but before it is pushed to the registry is the earliest and most effective security gate because the image has been fully assembled into its final layered form. This stage lets you catch vulnerabilities in the base OS packages, application dependencies, and any added binaries before the image is stored in a trusted registry and made available for deployment. By blocking the push of non-compliant images, you keep vulnerable artifacts out of the supply chain entirely, ensuring that only vetted images reach Kubernetes clusters or runtime environments.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CKS question from scratch — 845 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.