Courseiva
Supply Chain Security →easyMultiple Choice

CKS Supply Chain Security Practice Question

Which command is used with Cosign to sign a container image?

⚠ Common exam trap

The trap for CKS candidates is confusing the `cosign sign` command with `cosign attest` or `cosign verify`. Signing creates a signature artifact attached to the image, attestation adds a signed in-toto statement, and verification validates signatures. In the context of container supply chain security as tested on the CKS exam, understanding this distinction is key.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

cosign sign <image>

The `cosign sign <image>` command is used to sign a container image by attaching a digital signature to the image manifest in the container registry. This signature, typically stored as a separate tag or in an OCI artifact, allows verification of the image's origin and integrity using the corresponding public key.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    cosign verify <image>

    Why it's wrong here

    cosign verify is used to validate an existing signature against a public key or keyless authority; it performs signature verification and fails if no signature is present. Running it against an unsigned image yields an error such as 'no matching signatures', so it cannot satisfy a signing workflow. It is the read-only counterpart to signing, proving provenance rather than producing it.

  • ✗

    cosign attest <image>

    Why it's wrong here

    cosign attest generates an in-toto attestation (e.g., SLSA provenance or custom predicate) attached to an image, which is a separate supply-chain artifact from an OCI signature. While attestations can support policy verification, they are structured metadata statements rather than a hash-based signature over the image manifest. Signing an attestation is optional and does not replace the need for 'cosign sign' to sign the image itself.

  • ✓

    cosign sign <image>

    Why this is correct

    cosign sign is the dedicated command for signing a container image by creating an OCI signature object that references the image digest, either with a private key, a Cosign key pair, or keyless signing via Fulcio and Rekor. It computes a signature over the image manifest and stores the signature as a separate tag/artifact (e.g., sha256-...-key.sig) in the registry. This is the standard command for integrity and provenance verification workflows.

  • ✗

    cosign generate <image>

    Why it's wrong here

    cosign generate is not a recognized subcommand in the Cosign CLI; the documented sign/verify/attest command set does not include a 'generate' action. Users might confuse it with other tooling like 'cosign generate-key-pair' (which is actually 'cosign generate-key-pair') but there is no image-signing 'generate' operation. Typing it in modern Cosign versions returns 'unknown command' and exits, making it an ineffective option.

About these practice questions

Courseiva writes every CKS question from scratch — 845 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.