CKS Supply Chain Security Practice Question
Which Kubernetes admission controller ensures that a pod only uses images from a specific registry?
⚠ Common exam trap
The CKS exam often tests the distinction between AlwaysPullImages (which only affects pull behavior, not source validation) and ImagePolicyWebhook (which enforces registry restrictions), leading candidates to confuse operational controls with policy enforcement.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
ImagePolicyWebhook
The ImagePolicyWebhook admission controller allows you to define a webhook that validates container images against a policy, such as restricting them to a specific registry. When a pod is created, Kubernetes sends an admission review to the webhook, which can reject images not from the allowed registry. This is the correct choice because it directly enforces image source policies.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
NamespaceLifecycle
Why it's wrong here
NamespaceLifecycle only blocks creation in terminating namespaces and enforces namespace existence; it never inspects container image references. It is tempting because admission controllers do gate pod creation, and namespace-scoped policy feels adjacent, but registry restriction requires an image-policy webhook such as ImagePolicyWebhook or a policy engine.
- ✓
ImagePolicyWebhook
Why this is correct
ImagePolicyWebhook delegates admission decisions to an external HTTP service, which inspects each pod's image reference and rejects anything outside the permitted registry. Built-in controllers such as NodeRestriction or PodSecurityPolicy cannot enforce registry allow-lists, so this satisfies the stem's registry restriction.
- ✗
PodNodeSelector
Why it's wrong here
PodNodeSelector constrains which nodes a pod may schedule onto via node labels and selectors; it does not inspect image registries. It is tempting as a pod-admission policy, but registry restriction is enforced by an image policy webhook or admission controller that validates image references.
- ✗
AlwaysPullImages
Why it's wrong here
AlwaysPullImages forces kubelet to pull on every start, ensuring freshness, but it accepts any registry the pod spec names. It is tempting because it governs image behaviour at admission, yet the requirement is registry allow-listing, which needs an image-policy webhook evaluating the image field against permitted registries.
Go deeper
Related to this question
Learn chapter
Supply Chain Security: Container Image Security
Key term
Pod Security Admission
Pod Security Admission is a Kubernetes feature that enforces security standards on pods at creation time to prevent running containers with dangerous privileges.
Key term
Kyverno Policy Engine
Kyverno Policy Engine is a Kubernetes-native tool that enforces rules on resources to ensure security, compliance, and best practices across your cluster.
About these practice questions
This CKS question is part of Courseiva's 845-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.