Courseiva
Supply Chain Security →mediumMultiple Choice

CKS Supply Chain Security Practice Question

What is the correct way to specify a container image using a SHA digest instead of a tag for immutable deployments?

⚠ Common exam trap

The exam often tests the misconception that version tags (e.g., `1.0.0`) are immutable, but the trap here is that tags are mutable by default and only a digest reference provides cryptographic immutability for supply chain security.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

image: myapp@sha256:abc123...

Using the `@sha256:` syntax pins the container image to an immutable content digest, ensuring that every pull returns the exact same image regardless of tag updates. This eliminates the risk of tag mutability, where a tag like `latest` can be overwritten with a different image, breaking supply chain integrity and reproducibility.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    image: myapp:latest

    Why it's wrong here

    The 'latest' tag is a floating tag that is automatically overwritten whenever a new image is pushed without an explicit tag. This means the same tag can refer to different images over time, breaking reproducibility and potentially causing unexpected behavior in production. Because tags are mutable pointers, 'latest' does not guarantee any specific image content.

  • ✗

    image: myapp:stable

    Why it's wrong here

    The 'stable' tag, while sounding reliable, is simply another mutable tag that maintainers may update to point to the newest stable release. Since registries allow tags to be overwritten or moved, the same 'stable' tag can change to a different image without any fixed reference to the original content. This tag offers no cryptographic assurance of the image's identity.

  • ✓

    image: myapp@sha256:abc123...

    Why this is correct

    The digest (in the format sha256:...) is a cryptographic hash of the image manifest, making it a content-addressed identifier. Pulling by digest always fetches the exact same image, regardless of any tag changes, thereby ensuring reproducibility and supply-chain integrity. This is the correct way to specify an immutable container image reference.

  • ✗

    image: myapp:1.0.0

    Why it's wrong here

    A version tag like '1.0.0' appears immutable, but in practice it is still a mutable tag that maintainers can reassign to a different image, for example, to patch a bug or rebuild with a different base layer. Without an accompanying digest, you cannot verify that the tag points to the exact content you expect. Thus, version tags are not sufficient for secure, reproducible deployments.

About these practice questions

Courseiva writes every CKS question from scratch — 845 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.