CKS Supply Chain Security Practice Question
Which THREE are valid methods to enforce that only images from a specific registry can be deployed in a Kubernetes cluster? (Select three.)
⚠ Common exam trap
The CKS exam often tests that candidates confuse PodSecurityPolicy (PSP) with image registry validation, but PSP only controls pod security attributes, not image sources; the trap is assuming PSP can filter registries because it has 'policy' in its name.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
ImagePolicyWebhook admission controller
Option B (ImagePolicyWebhook admission controller) is correct because it is a built-in Kubernetes admission controller that calls an external HTTP webhook during admission to approve or reject a Pod based on its container image, so the webhook can enforce that images originate only from an allowed registry. Option C (Kyverno policy validating image registry) is correct because Kyverno is a Kubernetes-native admission policy engine whose validating policies can match on Pod specs and deny any container whose image field does not reference the approved registry. Option D (OPA/Gatekeeper constraint to validate registry) is correct because Gatekeeper runs OPA as a validating admission webhook and its ConstraintTemplates/Constraints (e.g., using Rego on input.review.object.spec.containers[_].image) can reject workloads that pull from unapproved registries. Option A (PodSecurityPolicy) is not correct because PSP only governed pod security attributes such as privileged mode, host namespaces, and volume types, not image registry provenance. Option E (NetworkPolicy) is not correct because it only controls L3/L4 network traffic (e.g., egress to registry IPs/ports) and cannot inspect or validate the image reference used in a Pod specification.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
PodSecurityPolicy (PSP)
Why it's wrong here
PSP is deprecated since v1.21 and removed in v1.25. It did not control image registries.
- ✓
ImagePolicyWebhook admission controller
Why this is correct
ImagePolicyWebhook delegates admission decisions to an external HTTPS service that inspects the pod's image reference and returns allow or deny. Configuring it to reject images outside the specified registry enforces the restriction at admission time, satisfying the registry-only deployment requirement.
- ✓
Kyverno policy validating image registry
Why this is correct
Kyverno's validating policies inspect pod specifications at admission and reject any image whose registry does not match the permitted value. This enforces the registry restriction cluster-wide without external webhook infrastructure, satisfying the requirement to allow only images from a specific registry.
- ✓
OPA/Gatekeeper constraint to validate registry
Why this is correct
An OPA/Gatekeeper constraint uses the Rego policy language to evaluate admission requests, rejecting any pod whose image field does not match the permitted registry prefix. This enforces the registry restriction at admission time, before the workload is persisted to etcd.
- ✗
NetworkPolicy to restrict egress to registries
Why it's wrong here
NetworkPolicy governs pod network traffic, not admission of images at deployment time. It tempts because blocking egress to unauthorised registries seems to prevent pulls, but images already present or pulled via allowed paths still deploy, so registry enforcement fails.
Go deeper
Related to this question
Learn chapter
Supply Chain Security: Container Image Security
Key term
OPA Gatekeeper
OPA Gatekeeper is a Kubernetes admission controller that enforces custom security and compliance policies on resources before they are created or updated in a cluster.
Key term
Pod Security Admission
Pod Security Admission is a Kubernetes feature that enforces security standards on pods at creation time to prevent running containers with dangerous privileges.
About these practice questions
One of 845 original CKS practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.