Courseiva
Supply Chain Security →easyMultiple Choice

CKS Supply Chain Security Practice Question

Which Kubernetes admission controller ensures that a pod only uses images from a specific registry?

⚠ Common exam trap

The CKS exam often tests the distinction between AlwaysPullImages (which only affects pull behavior, not source validation) and ImagePolicyWebhook (which enforces registry restrictions), leading candidates to confuse operational controls with policy enforcement.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

ImagePolicyWebhook

The ImagePolicyWebhook admission controller allows you to define a webhook that validates container images against a policy, such as restricting them to a specific registry. When a pod is created, Kubernetes sends an admission review to the webhook, which can reject images not from the allowed registry. This is the correct choice because it directly enforces image source policies.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    NamespaceLifecycle

    Why it's wrong here

    NamespaceLifecycle only blocks creation in terminating namespaces and enforces namespace existence; it never inspects container image references. It is tempting because admission controllers do gate pod creation, and namespace-scoped policy feels adjacent, but registry restriction requires an image-policy webhook such as ImagePolicyWebhook or a policy engine.

  • ✓

    ImagePolicyWebhook

    Why this is correct

    ImagePolicyWebhook delegates admission decisions to an external HTTP service, which inspects each pod's image reference and rejects anything outside the permitted registry. Built-in controllers such as NodeRestriction or PodSecurityPolicy cannot enforce registry allow-lists, so this satisfies the stem's registry restriction.

  • ✗

    PodNodeSelector

    Why it's wrong here

    PodNodeSelector constrains which nodes a pod may schedule onto via node labels and selectors; it does not inspect image registries. It is tempting as a pod-admission policy, but registry restriction is enforced by an image policy webhook or admission controller that validates image references.

  • ✗

    AlwaysPullImages

    Why it's wrong here

    AlwaysPullImages forces kubelet to pull on every start, ensuring freshness, but it accepts any registry the pod spec names. It is tempting because it governs image behaviour at admission, yet the requirement is registry allow-listing, which needs an image-policy webhook evaluating the image field against permitted registries.

About these practice questions

This CKS question is part of Courseiva's 845-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.