CKS Supply Chain Security Practice Question
What is the purpose of an SBOM (Software Bill of Materials) in the context of supply chain security?
⚠ Common exam trap
Candidates often confuse the purpose of an SBOM with that of a vulnerability scanner or a signing tool; candidates often pick 'scan images for vulnerabilities' because SBOMs are used in vulnerability management, but the SBOM itself is only the inventory.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
To provide a list of all software components and dependencies in an artifact
An SBOM is a formal, machine-readable inventory of all software components, libraries, and dependencies that make up an artifact such as a container image. Its purpose is to provide transparency into the supply chain so that when a new vulnerability is disclosed, you can quickly determine whether your artifact contains the affected component. It does not itself perform signing, scanning, or runtime enforcement.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
To sign container images
Why it's wrong here
An SBOM is a structured, machine-readable inventory that catalogs the components, versions, and dependencies contained in a software artifact. It does not provide cryptographic signatures, which is the role of tools like Cosign that generate and verify signatures for container images. Signing attests to integrity and provenance at build time, whereas an SBOM simply describes what is inside the artifact.
- ✗
To scan images for vulnerabilities
Why it's wrong here
Vulnerability scanning is a process that compares the components listed in an SBOM against known vulnerability databases to detect exposures. The SBOM itself does not perform any scanning; it is the input data that a scanner like Trivy or Grype consumes. Therefore, while an SBOM enables scanning by providing component transparency, it is not a scanning tool.
- ✓
To provide a list of all software components and dependencies in an artifact
Why this is correct
An SBOM (Software Bill of Materials) is a formal, structured record that enumerates every software component, library, package, and dependency included in an artifact, along with metadata such as version numbers and often licenses. It provides a complete supply-chain inventory, making it possible to trace exactly which code is present and why it was included. This transparency is foundational for license compliance, security analysis, and incident response.
- ✗
To enforce runtime security policies
Why it's wrong here
Runtime security policies actively enforce constraints on behavior during execution, using mechanisms such as seccomp profiles, AppArmor, SELinux, or eBPF-based tools like Falco to block dangerous syscalls or actions. An SBOM is a static, declarative document that does not run in the environment or interact with the kernel. It provides information about components, not active controls, so it cannot enforce or monitor runtime activity.
Go deeper
Related to this question
About these practice questions
This CKS question is part of Courseiva's 845-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CNCF exam blueprint
This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.