Courseiva
Supply Chain Security →mediumMultiple Choice

CKS Supply Chain Security Practice Question

To verify a signed container image, which command should be used?

⚠ Common exam trap

The CNCF-CKS exam often tests the distinction between `cosign verify` and `cosign validate` (or similar-sounding commands), where candidates confuse signature verification with attestation verification or assume a generic 'validate' verb exists, leading them to pick a plausible but incorrect option.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

cosign verify myimage:latest

The `cosign verify` command is the correct tool for verifying the cryptographic signature of a signed container image stored in an OCI-compliant registry. Cosign, part of the Sigstore project, uses public-key or keyless signing to ensure image integrity and authenticity. The command checks the signature against the image manifest and the provided public key or Fulcio certificate, confirming that the image has not been tampered with since signing.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    cosign verify myimage:latest

    Why this is correct

    cosign verify validates a container image's signature against the specified public key or keyless identity, confirming the image was signed by a trusted party and has not been tampered with. This is the standard Sigstore command for signature verification in supply-chain security workflows.

  • ✗

    trivy verify myimage:latest

    Why it's wrong here

    Trivy scans images for vulnerabilities and misconfigurations; it does not verify cryptographic signatures. It is tempting because Trivy is a familiar container security tool, and it would be correct for CVE scanning in a pipeline, but signature validation requires cosign verify against the signer's key.

  • ✗

    kubectl verify myimage:latest

    Why it's wrong here

    kubectl has no verify subcommand; it manages cluster resources and cannot validate image signatures. It is tempting because kubectl is the everyday Kubernetes tool, and it would be right for inspecting pods or deployments, but signature verification needs a dedicated supply-chain tool such as cosign.

  • ✗

    cosign validate myimage:latest

    Why it's wrong here

    cosign's verification subcommand is verify, not validate, so this syntax fails before any signature check runs. Cosign is the correct tool for checking signatures against a public key or keyless identity; the error is purely the wrong verb, and cosign verify myimage:latest would work.

About these practice questions

One of 845 original CKS practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.