CKS Supply Chain Security Practice Question
Which of the following is a static analysis tool for Kubernetes manifests that can be used to find misconfigurations?
⚠ Common exam trap
The CKS exam often tests the distinction between tools that scan container images (like Trivy) versus tools that scan Kubernetes manifest files (like Kubesec), causing candidates to confuse vulnerability scanning with static configuration analysis.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Kubesec
Kubesec is a static analysis tool specifically designed to evaluate Kubernetes manifests against a set of built-in security policies. It scans YAML or JSON resource definitions and assigns a risk score based on misconfigurations such as running containers as root, missing resource limits, or insecure capability assignments. This makes it the correct choice for identifying misconfigurations in Kubernetes manifests without executing them.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Trivy
Why it's wrong here
Trivy scans container images, filesystems and IaC for vulnerabilities and misconfigurations, but it is not the manifest-focused static analyser this question targets. It is tempting because Trivy does detect some Kubernetes misconfigurations, and it would be correct for image vulnerability scanning.
- ✓
Kubesec
Why this is correct
Kubesec parses Kubernetes manifests statically and scores them against security checks such as privileged containers, host mounts and missing resource limits. This satisfies the stem's requirement for a static manifest analysis tool without needing a running cluster.
- ✗
Syft
Why it's wrong here
Syft generates software bills of materials from container images and filesystems; it does not parse Kubernetes YAML for misconfigurations. It is tempting because SBOM generation is a supply-chain security task, and Syft would be correct when you need to inventory packages inside an image.
- ✗
Cosign
Why it's wrong here
Cosign signs and verifies container images and attestations; it does not analyse Kubernetes manifest content for misconfigurations. It is tempting because signing is a supply-chain security control, and Cosign would be correct when you need to verify image signatures before admission.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CKS question from scratch — 845 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.