Courseiva
Supply Chain Security →mediumMultiple Choice

CKS Supply Chain Security Practice Question

Which of the following is a static analysis tool for Kubernetes manifests that can be used to find misconfigurations?

⚠ Common exam trap

The CKS exam often tests the distinction between tools that scan container images (like Trivy) versus tools that scan Kubernetes manifest files (like Kubesec), causing candidates to confuse vulnerability scanning with static configuration analysis.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Kubesec

Kubesec is a static analysis tool specifically designed to evaluate Kubernetes manifests against a set of built-in security policies. It scans YAML or JSON resource definitions and assigns a risk score based on misconfigurations such as running containers as root, missing resource limits, or insecure capability assignments. This makes it the correct choice for identifying misconfigurations in Kubernetes manifests without executing them.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Trivy

    Why it's wrong here

    Trivy scans container images, filesystems and IaC for vulnerabilities and misconfigurations, but it is not the manifest-focused static analyser this question targets. It is tempting because Trivy does detect some Kubernetes misconfigurations, and it would be correct for image vulnerability scanning.

  • ✓

    Kubesec

    Why this is correct

    Kubesec parses Kubernetes manifests statically and scores them against security checks such as privileged containers, host mounts and missing resource limits. This satisfies the stem's requirement for a static manifest analysis tool without needing a running cluster.

  • ✗

    Syft

    Why it's wrong here

    Syft generates software bills of materials from container images and filesystems; it does not parse Kubernetes YAML for misconfigurations. It is tempting because SBOM generation is a supply-chain security task, and Syft would be correct when you need to inventory packages inside an image.

  • ✗

    Cosign

    Why it's wrong here

    Cosign signs and verifies container images and attestations; it does not analyse Kubernetes manifest content for misconfigurations. It is tempting because signing is a supply-chain security control, and Cosign would be correct when you need to verify image signatures before admission.

About these practice questions

Courseiva writes every CKS question from scratch — 845 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.