Courseiva
Supply Chain Security →easyMultiple Choice

CKS Supply Chain Security Practice Question

What is the primary purpose of an SBOM in supply chain security?

⚠ Common exam trap

The CKS exam often tests the distinction between an SBOM (a list of components) and image signing (a cryptographic verification), causing candidates to confuse the two because both are part of supply chain security but serve different purposes.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

To list all open source and third-party components in an image

An SBOM (Software Bill of Materials) is a formal, machine-readable inventory of all components—including open source and third-party libraries—used to build a software artifact. In supply chain security, its primary purpose is to provide transparency and enable vulnerability tracking by listing every dependency, so that when a new CVE is disclosed, teams can quickly determine if their images are affected. This aligns directly with option A.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    To list all open source and third-party components in an image

    Why this is correct

    An SBOM (Software Bill of Materials) is a formal, machine-readable inventory that enumerates all open source and third-party components, their exact versions, and dependency relationships inside a container image. Its primary purpose is to provide transparency and traceability for software supply chain security, enabling vulnerability correlation, license compliance, and provenance verification. Without an SBOM, you cannot systematically identify which component is affected by a newly disclosed CVE or audit what third-party code actually ships in production.

  • ✗

    To scan images for secrets

    Why it's wrong here

    Scanning container images for secrets is a distinct security control performed by dedicated tools (e.g., Trivy, Snyk, or git-secrets) that search filesystem layers for hardcoded credentials, API keys, and private certificates. An SBOM does not inspect file contents or look for sensitive data; it only catalogs software component metadata already declared during the build. Treating SBOM generation as a secret scanner creates a false sense of security, because leaked tokens would never be listed in a bill of materials.

  • ✗

    To sign container images

    Why it's wrong here

    Container image signing is a cryptographic operation, typically using tools like cosign or sigstore, that creates a digital signature bound to an image digest to verify its integrity and publisher identity. An SBOM is not a signature; it is a declarative document that lists components, and it can be signed separately (e.g., as an attestation) but its purpose is inventory, not authenticity. Confusing these two mechanisms ignores that signing proves who built the image, while an SBOM proves what is inside it.

  • ✗

    To enforce network policies

    Why it's wrong here

    Network policies in Kubernetes are implemented as NetworkPolicy resources that control pod-to-pod or pod-to-service traffic based on labels, IP addresses, and ports, enforced by the CNI plugin. An SBOM has no relationship to traffic flow or cluster networking; it is a software artifact that describes dependencies for supply chain analysis. Assigning the role of network policy enforcement to an SBOM conflates runtime network layer controls with build-time component transparency, which are entirely different domains.

About these practice questions

One of 845 original CKS practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.