CKS Supply Chain Security Practice Question
To verify a signed container image, which command should be used?
⚠ Common exam trap
The CNCF-CKS exam often tests the distinction between `cosign verify` and `cosign validate` (or similar-sounding commands), where candidates confuse signature verification with attestation verification or assume a generic 'validate' verb exists, leading them to pick a plausible but incorrect option.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
cosign verify myimage:latest
The `cosign verify` command is the correct tool for verifying the cryptographic signature of a signed container image stored in an OCI-compliant registry. Cosign, part of the Sigstore project, uses public-key or keyless signing to ensure image integrity and authenticity. The command checks the signature against the image manifest and the provided public key or Fulcio certificate, confirming that the image has not been tampered with since signing.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
cosign verify myimage:latest
Why this is correct
cosign verify validates a container image's signature against the specified public key or keyless identity, confirming the image was signed by a trusted party and has not been tampered with. This is the standard Sigstore command for signature verification in supply-chain security workflows.
- ✗
trivy verify myimage:latest
Why it's wrong here
Trivy scans images for vulnerabilities and misconfigurations; it does not verify cryptographic signatures. It is tempting because Trivy is a familiar container security tool, and it would be correct for CVE scanning in a pipeline, but signature validation requires cosign verify against the signer's key.
- ✗
kubectl verify myimage:latest
Why it's wrong here
kubectl has no verify subcommand; it manages cluster resources and cannot validate image signatures. It is tempting because kubectl is the everyday Kubernetes tool, and it would be right for inspecting pods or deployments, but signature verification needs a dedicated supply-chain tool such as cosign.
- ✗
cosign validate myimage:latest
Why it's wrong here
cosign's verification subcommand is verify, not validate, so this syntax fails before any signature check runs. Cosign is the correct tool for checking signatures against a public key or keyless identity; the error is purely the wrong verb, and cosign verify myimage:latest would work.
Go deeper
Related to this question
Learn chapter
Cluster Hardening: Node and Container Security
Key term
Image Signing and Verification
Image signing and verification is the process of digitally signing a container image to prove its origin and integrity, and then checking that signature before using the image to ensure it was not tampered with.
About these practice questions
One of 845 original CKS practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.