CKS Supply Chain Security Practice Question
What is the correct way to specify a container image using a SHA digest instead of a tag for immutable deployments?
⚠ Common exam trap
The exam often tests the misconception that version tags (e.g., `1.0.0`) are immutable, but the trap here is that tags are mutable by default and only a digest reference provides cryptographic immutability for supply chain security.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
image: myapp@sha256:abc123...
Using the `@sha256:` syntax pins the container image to an immutable content digest, ensuring that every pull returns the exact same image regardless of tag updates. This eliminates the risk of tag mutability, where a tag like `latest` can be overwritten with a different image, breaking supply chain integrity and reproducibility.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
image: myapp:latest
Why it's wrong here
The 'latest' tag is a floating tag that is automatically overwritten whenever a new image is pushed without an explicit tag. This means the same tag can refer to different images over time, breaking reproducibility and potentially causing unexpected behavior in production. Because tags are mutable pointers, 'latest' does not guarantee any specific image content.
- ✗
image: myapp:stable
Why it's wrong here
The 'stable' tag, while sounding reliable, is simply another mutable tag that maintainers may update to point to the newest stable release. Since registries allow tags to be overwritten or moved, the same 'stable' tag can change to a different image without any fixed reference to the original content. This tag offers no cryptographic assurance of the image's identity.
- ✓
image: myapp@sha256:abc123...
Why this is correct
The digest (in the format sha256:...) is a cryptographic hash of the image manifest, making it a content-addressed identifier. Pulling by digest always fetches the exact same image, regardless of any tag changes, thereby ensuring reproducibility and supply-chain integrity. This is the correct way to specify an immutable container image reference.
- ✗
image: myapp:1.0.0
Why it's wrong here
A version tag like '1.0.0' appears immutable, but in practice it is still a mutable tag that maintainers can reassign to a different image, for example, to patch a bug or rebuild with a different base layer. Without an accompanying digest, you cannot verify that the tag points to the exact content you expect. Thus, version tags are not sufficient for secure, reproducible deployments.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CKS question from scratch — 845 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.