Courseiva

CKS · topic practice

Supply Chain Security practice questions

Supply Chain Security covers hardening how images are built, stored, verified, and admitted into the cluster. Expect tasks on scanning images with Trivy, generating SBOMs, signing with Cosign, pinning images by digest, and enforcing policies via admission controllers like Kyverno or OPA Gatekeeper. Questions test both conceptual controls and hands-on YAML edits.

Courseiva uses original exam-style practice questions designed for learning and revision. The goal is to understand the concepts, recognise exam patterns, and improve through explanations — not memorise copied exam dumps.

Editorial oversight:Johnson Ajibi· MSc IT Security, IEEE Senior Member
20 questionsDomain: Supply Chain Security

What the exam tests

What to know about Supply Chain Security

Be able to scan images, generate an SBOM, sign and verify with Cosign, and write an admission policy that blocks unsigned or untrusted-registry images. The most important thing: pin images by SHA digest and ensure your policy actually enforces it at admission time.

Scanning images for CVEs using Trivy and interpreting severity output

Generating and inspecting SBOMs with tools like Syft or Trivy

Enforcing image digest pinning and signature verification in Deployment YAML

Applying admission policies with Kyverno or OPA Gatekeeper to restrict registries

Watch out for

Common Supply Chain Security exam traps

  • ▸Using mutable tags instead of SHA digests, which defeats integrity guarantees and fails policy checks
  • ▸Confusing SBOM generation with vulnerability scanning; they are distinct artifacts and tools
  • ▸Forgetting that admission controllers must be installed and webhook-configured before policies take effect

Practice set

Supply Chain Security questions

20 questions · select your answer, then reveal the explanation

Which THREE of the following are required to implement a secure software supply chain using Kubernetes native features?

You are securing a Kubernetes cluster that runs workloads from multiple teams. The cluster uses a private container registry and an admission controller to enforce image policies. Which TWO of the following actions are most effective in preventing the use of unapproved or tampered container images? (Choose two correct answers.)

You are configuring an ImagePolicyWebhook admission controller to allow only images from a trusted registry 'trusted-registry.io'. Which flag must be set in the kube-apiserver configuration to enable the webhook?

A cluster uses ImagePolicyWebhook admission controller. After configuring it, deployments referencing images from an unauthorized registry are blocked. However, some deployments are still being admitted. What is a possible cause?

Which tool can be used to generate an SBOM (Software Bill of Materials) for a container image?

An OPA/Gatekeeper constraint requires that all images' registries match a pattern. A Deployment uses 'myregistry.io/app:v1'. The admission controller rejects it. The admin runs 'kubectl get constraints' and sees the constraint is active. What is the next debugging step?

A cluster has both ImagePolicyWebhook and a mutating webhook that adds a sidecar. The admin notices that even when ImagePolicyWebhook rejects an image, the mutating webhook has already added the sidecar. What admission ordering issue is occurring?

A security team wants to ensure that only signed images are deployed in the cluster. They have set up an ImagePolicyWebhook admission controller. After configuring the webhook, they notice that pods with unsigned images are still being created. What is the most likely cause?

Which of the following is a best practice for securing container images?

An administrator applies the following Kyverno policy to the cluster. What is the effect of this policy?

apiVersion: kyverno.io/v1 kind: ClusterPolicy metadata: name: require-non-root spec: validationFailureAction: enforce rules: - name: check-runAsNonRoot match: resources: kinds: - Pod validate: message: "Running as root is not allowed." pattern: spec: securityContext: runAsNonRoot: true

A cluster administrator notices that a pod using an image from a public registry is failing to start. The image was signed with Cosign, and the cluster has an ImagePolicyWebhook configured to require signatures. The error message from the webhook indicates 'signature verification failed'. What is the most likely cause?

Which TWO of the following are correct methods to verify a signed container image using Cosign?

Which admission controller runs FIRST in the Kubernetes admission flow?

A security team wants to generate an SBOM for a container image. Which tool should they use?

An administrator runs 'kubectl run test-pod --image=nginx:latest' and the pod fails to start. The event log shows 'ImagePullBackOff' with error 'manifest for nginx:latest not found: manifest unknown'. The image 'nginx:latest' exists in the registry. What is the most likely cause?

Which admission controller is responsible for invoking external webhooks to validate or mutate resources?

An administrator wants to ensure that all containers in a deployment run as a non-root user. Which YAML snippet correctly sets the security context to run as user ID 1000?

Which admission controller is responsible for validating and modifying images based on an external webhook in Kubernetes?

An OPA/Gatekeeper constraint is configured to require all container images to be from a specific registry. A user creates a Pod with image 'gcr.io/myimage:v1'. Which admission controller will first reject this Pod?

Which command would scan a Kubernetes Pod manifest for security issues?

Free account

Track your progress over time

Create a free account to save your results and see which topics improve across sessions.

Focused Supply Chain Security sessions

Start a Supply Chain Security only practice session

Every question in these sessions is drawn from the Supply Chain Security domain — nothing else.

Related practice questions

Related CKS topic practice pages

Move into related areas when this topic feels solid.

Frequently asked questions

What does the CKS exam test about Supply Chain Security?
Be able to scan images, generate an SBOM, sign and verify with Cosign, and write an admission policy that blocks unsigned or untrusted-registry images. The most important thing: pin images by SHA digest and ensure your policy actually enforces it at admission time.
How should I use these practice questions?
Select your answer before revealing the explanation. Then read why each option is right or wrong — this active recall approach builds retention far faster than re-reading notes.
Can I practise just Supply Chain Security questions in a focused session?
Yes — the session launcher on this page draws every question from the Supply Chain Security domain. Use a 10-question session first to gauge your baseline, then move to 20 or 30 once the weak spots are clear.
Where can I practise other CKS topics?
Use the topic links above to move to related areas, or go back to the CKS question bank to see all topics.
Are these real exam questions or dumps?
These are original practice questions written to test the same concepts the CKS exam covers. They are not copied from any real exam or dump site.