Courseiva
Supply Chain Security →mediumMultiple Choice

CKS Supply Chain Security Practice Question

Which command is used to sign a container image with Cosign and store the signature in an OCI registry?

⚠ Common exam trap

CNCF-CKS often tests the distinction between signing (`cosign sign`) and verifying (`cosign verify`), and the trap here is that candidates may confuse the `attach` subcommand (used for non-signature artifacts) with the signing process, or assume a non-existent `docker-sign` subcommand is valid.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

cosign sign --key cosign.key myimage:latest

`cosign sign --key cosign.key myimage:latest` is the standard Cosign command to sign a container image using a private key and store the resulting signature in the OCI registry as an attached artifact (e.g., a `.sig` layer). This command generates a signature that is automatically pushed to the same registry alongside the image, enabling verification without external storage.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    cosign docker-sign myimage:latest

    Why it's wrong here

    Cosign has no docker-sign subcommand, so the command fails immediately. It is tempting because signing a Docker image is the goal, but the actual syntax is cosign sign, which writes the signature to the OCI registry.

  • ✗

    cosign verify --key cosign.pub myimage:latest

    Why it's wrong here

    verify checks an existing signature against a public key; it does not create or upload one. It is the correct command when validating that a signed image is authentic, but the question asks for the signing operation itself.

  • ✓

    cosign sign --key cosign.key myimage:latest

    Why this is correct

    Cosign's sign subcommand with --key uses the supplied private key to create a signature, then uploads it to the same OCI registry as the image, attaching it as a referrer artefact. This satisfies the requirement to store the signature in the registry itself.

  • ✗

    cosign attach signature --key cosign.key myimage:latest

    Why it's wrong here

    attach signature is not a valid Cosign subcommand; signatures are created and pushed by cosign sign. It is tempting because attaching a signature to an image describes the outcome, yet the tool provides no such verb.

About these practice questions

Courseiva writes every CKS question from scratch — 845 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

4 more ways this is tested on CKS

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. Which kubectl command signs a container image using Cosign?

medium
  • A.crictl sign myimage:latest
  • B.kubectl sign image myimage:latest
  • ✓ C.cosign sign myimage:latest
  • D.kubectl cosign sign myimage:latest

Why C: Cosign is a standalone tool for signing and verifying container images, not a kubectl subcommand. The correct command is `cosign sign myimage:latest`, which signs the image and stores the signature in an OCI-compliant registry alongside the image. This is part of the supply chain security workflow for ensuring image integrity and provenance.

Variation 2. Which command is used to sign a container image with Cosign?

easy
  • A.cosign attest
  • ✓ B.cosign sign
  • C.cosign generate
  • D.cosign verify

Why B: The `cosign sign` command is used to sign container images and other artifacts, creating a digital signature that is stored alongside the image in the registry. This signature can later be verified with `cosign verify` to ensure the image's integrity and origin. The other options serve different purposes: `cosign attest` attaches an in-toto attestation, `cosign generate` creates key pairs, and `cosign verify` checks signatures.

Variation 3. Which command is used with Cosign to sign a container image?

easy
  • A.cosign verify <image>
  • B.cosign attest <image>
  • ✓ C.cosign sign <image>
  • D.cosign generate <image>

Why C: The `cosign sign <image>` command is used to sign a container image by attaching a digital signature to the image manifest in the container registry. This signature, typically stored as a separate tag or in an OCI artifact, allows verification of the image's origin and integrity using the corresponding public key.

Variation 4. Which command would you use to sign a container image with Cosign?

easy
  • A.cosign push <image>
  • B.cosign verify <image>
  • C.cosign attest <image>
  • ✓ D.cosign sign <image>

Why D: The `cosign sign <image>` command is used to sign a container image with Cosign, attaching a digital signature to the image manifest in the container registry. This signature can later be verified to ensure the image's integrity and origin, which is a core requirement for supply chain security in Kubernetes environments.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.