Courseiva
Supply Chain Security →mediumMultiple Choice

CKS Supply Chain Security Practice Question

What is the purpose of an SBOM (Software Bill of Materials) in the context of supply chain security?

⚠ Common exam trap

Candidates often confuse the purpose of an SBOM with that of a vulnerability scanner or a signing tool; candidates often pick 'scan images for vulnerabilities' because SBOMs are used in vulnerability management, but the SBOM itself is only the inventory.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

To provide a list of all software components and dependencies in an artifact

An SBOM is a formal, machine-readable inventory of all software components, libraries, and dependencies that make up an artifact such as a container image. Its purpose is to provide transparency into the supply chain so that when a new vulnerability is disclosed, you can quickly determine whether your artifact contains the affected component. It does not itself perform signing, scanning, or runtime enforcement.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    To sign container images

    Why it's wrong here

    An SBOM is a structured, machine-readable inventory that catalogs the components, versions, and dependencies contained in a software artifact. It does not provide cryptographic signatures, which is the role of tools like Cosign that generate and verify signatures for container images. Signing attests to integrity and provenance at build time, whereas an SBOM simply describes what is inside the artifact.

  • ✗

    To scan images for vulnerabilities

    Why it's wrong here

    Vulnerability scanning is a process that compares the components listed in an SBOM against known vulnerability databases to detect exposures. The SBOM itself does not perform any scanning; it is the input data that a scanner like Trivy or Grype consumes. Therefore, while an SBOM enables scanning by providing component transparency, it is not a scanning tool.

  • ✓

    To provide a list of all software components and dependencies in an artifact

    Why this is correct

    An SBOM (Software Bill of Materials) is a formal, structured record that enumerates every software component, library, package, and dependency included in an artifact, along with metadata such as version numbers and often licenses. It provides a complete supply-chain inventory, making it possible to trace exactly which code is present and why it was included. This transparency is foundational for license compliance, security analysis, and incident response.

  • ✗

    To enforce runtime security policies

    Why it's wrong here

    Runtime security policies actively enforce constraints on behavior during execution, using mechanisms such as seccomp profiles, AppArmor, SELinux, or eBPF-based tools like Falco to block dangerous syscalls or actions. An SBOM is a static, declarative document that does not run in the environment or interact with the kernel. It provides information about components, not active controls, so it cannot enforce or monitor runtime activity.

About these practice questions

This CKS question is part of Courseiva's 845-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CNCF exam blueprint

This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.