CKS Supply Chain Security Practice Question
Which command would you use to sign a container image with Cosign?
⚠ Common exam trap
The exam often tests the distinction between `cosign sign` (which signs the image) and `cosign attest` (which creates a signed attestation about the image's metadata), causing candidates to confuse the two commands.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
cosign sign <image>
The `cosign sign <image>` command is used to sign a container image with Cosign, attaching a digital signature to the image manifest in the container registry. This signature can later be verified to ensure the image's integrity and origin, which is a core requirement for supply chain security in Kubernetes environments.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
cosign push <image>
Why it's wrong here
Cosign has no push subcommand; images are uploaded with docker push or crane, while cosign writes signatures and attestations to the registry. It is tempting because signing does involve pushing artefacts, and a push-style command would fit if the task were publishing the image itself.
- ✗
cosign verify <image>
Why it's wrong here
Verify checks an existing signature against a public key or certificate; it does not create one. It is tempting because it uses the same key material and registry, and would be the correct command when validating that an image was signed before admitting it to a cluster.
- ✗
cosign attest <image>
Why it's wrong here
Attest attaches a signed attestation, such as an SBOM or provenance predicate, to an image rather than producing a signature over the image digest. It is tempting because attest also invokes signing keys and writes to the registry, and would be the right command when recording metadata claims.
- ✓
cosign sign <image>
Why this is correct
Cosign signs container images stored in an OCI registry, binding a signature to the image digest. Running cosign sign against the image reference creates and uploads that signature, satisfying the requirement to cryptographically sign the container image.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CKS question from scratch — 845 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.