Courseiva
Supply Chain Security →mediumMultiple Choice

CKS Supply Chain Security Practice Question

Which Kyverno policy action is used to automatically mutate a resource to add a sidecar container for security?

⚠ Common exam trap

The CKS exam often tests the distinction between `mutate` and `validate` by describing a scenario that requires a change to the resource, leading candidates to incorrectly choose `validate` because they confuse 'enforcing a policy' with 'modifying the resource'.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

mutate

The `mutate` action in Kyverno is specifically designed to modify incoming Kubernetes resources before they are persisted. Adding a sidecar container (e.g., a security agent like Istio or Falco) is a classic mutation use case, where the policy patches the Pod spec to inject the container definition. This is distinct from validation, image verification, or resource generation.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    validate

    Why it's wrong here

    validate only permits or denies a resource against a rule; it cannot add a sidecar container to the Pod. It is tempting because validate is the most commonly used Kyverno action and enforces security policy at admission, and would be correct if the goal were to block non-compliant Pods rather than mutate them.

  • ✗

    verifyImages

    Why it's wrong here

    verifyImages checks container image signatures against attestors and rejects or allows workloads; it never alters the Pod spec to insert a container. It is tempting because it is a supply-chain security control applied at admission, and would be correct when the requirement is to enforce signed images rather than inject a sidecar.

  • ✓

    mutate

    Why this is correct

    Kyverno's `mutate` action rewrites matching resources during admission, applying JSON patches or strategic merge to inject the sidecar container automatically. This satisfies the stem's requirement for automatic modification, unlike `validate`, which only permits or denies requests without altering them.

  • ✗

    generate

    Why it's wrong here

    The generate rule creates new resources, such as cloning a ConfigMap or Secret into another namespace; it cannot modify an existing Pod spec to inject a container. It is tempting because generate also produces sidecar-like auxiliary objects, and would be correct when a policy must create a separate resource rather than patch one.

About these practice questions

This CKS question is part of Courseiva's 845-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.