CKS Supply Chain Security Practice Question
Which command is used to sign a container image with Cosign?
⚠ Common exam trap
A common pitfall on the CKS exam is confusing `cosign sign` (which creates a signature) with `cosign attest` (which creates an in-toto attestation) or `cosign verify` (which checks a signature). Candidates must remember that `sign` is the action that produces the cryptographic signature, while `verify` and `attest` are separate operations.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
cosign sign
The `cosign sign` command is used to sign container images and other artifacts, creating a digital signature that is stored alongside the image in the registry. This signature can later be verified with `cosign verify` to ensure the image's integrity and origin. The other options serve different purposes: `cosign attest` attaches an in-toto attestation, `cosign generate` creates key pairs, and `cosign verify` checks signatures.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
cosign attest
Why it's wrong here
cosign attest creates an in-toto attestation (a signed statement about the image's build provenance or test results) rather than simply signing the image itself. Although the attestation is cryptographically signed, the command's primary purpose is to attach metadata to an existing image, not to produce a standalone container signature that proves image identity. Using `cosign attest` without a separate `cosign sign` would leave the image without the conventional signature that image admission controllers expect.
- ✓
cosign sign
Why this is correct
cosign sign is the exact command that generates a digital signature for a container image, producing a signature payload stored in an OCI registry (typically as an image tag suffixed with `-sig`). It signs the image digest using a key pair, and the resulting signature can later be verified with `cosign verify`. This command is the core mechanism for asserting the identity of the signer and ensuring the image's content has not been tampered with.
- ✗
cosign generate
Why it's wrong here
cosign generate is used to create a key pair (private and public keys) for signing, often alongside `cosign generate-key-pair`, and it does not interact with a container image at all. It merely produces the cryptographic material that would later be used by `cosign sign`. Running `cosign generate` on its own leaves the image unsigned, so it is not the command that performs the actual signing operation.
- ✗
cosign verify
Why it's wrong here
cosign verify is intended for checking an existing signature against a container image, not for creating a signature. It takes as input a reference to the image and the public key (or a keyless verification endpoint) to validate that the image was signed by a trusted party. Since verification consumes a signature, it must be run after `cosign sign`, and using it to try to sign an image would fail because it does not write any signature data to the registry.
Go deeper
Related to this question
Learn chapter
Cluster Hardening: Node and Container Security
Key term
Image Signing and Verification
Image signing and verification is the process of digitally signing a container image to prove its origin and integrity, and then checking that signature before using the image to ensure it was not tampered with.
About these practice questions
One of 845 original CKS practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.