Courseiva
Supply Chain Security →hardMultiple Select

CKS Supply Chain Security Practice Question

Which THREE are valid methods to enforce that only images from a specific registry can be deployed in a Kubernetes cluster? (Select three.)

⚠ Common exam trap

The CKS exam often tests that candidates confuse PodSecurityPolicy (PSP) with image registry validation, but PSP only controls pod security attributes, not image sources; the trap is assuming PSP can filter registries because it has 'policy' in its name.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

ImagePolicyWebhook admission controller

Option B (ImagePolicyWebhook admission controller) is correct because it is a built-in Kubernetes admission controller that calls an external HTTP webhook during admission to approve or reject a Pod based on its container image, so the webhook can enforce that images originate only from an allowed registry. Option C (Kyverno policy validating image registry) is correct because Kyverno is a Kubernetes-native admission policy engine whose validating policies can match on Pod specs and deny any container whose image field does not reference the approved registry. Option D (OPA/Gatekeeper constraint to validate registry) is correct because Gatekeeper runs OPA as a validating admission webhook and its ConstraintTemplates/Constraints (e.g., using Rego on input.review.object.spec.containers[_].image) can reject workloads that pull from unapproved registries. Option A (PodSecurityPolicy) is not correct because PSP only governed pod security attributes such as privileged mode, host namespaces, and volume types, not image registry provenance. Option E (NetworkPolicy) is not correct because it only controls L3/L4 network traffic (e.g., egress to registry IPs/ports) and cannot inspect or validate the image reference used in a Pod specification.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    PodSecurityPolicy (PSP)

    Why it's wrong here

    PSP is deprecated since v1.21 and removed in v1.25. It did not control image registries.

  • ✓

    ImagePolicyWebhook admission controller

    Why this is correct

    ImagePolicyWebhook delegates admission decisions to an external HTTPS service that inspects the pod's image reference and returns allow or deny. Configuring it to reject images outside the specified registry enforces the restriction at admission time, satisfying the registry-only deployment requirement.

  • ✓

    Kyverno policy validating image registry

    Why this is correct

    Kyverno's validating policies inspect pod specifications at admission and reject any image whose registry does not match the permitted value. This enforces the registry restriction cluster-wide without external webhook infrastructure, satisfying the requirement to allow only images from a specific registry.

  • ✓

    OPA/Gatekeeper constraint to validate registry

    Why this is correct

    An OPA/Gatekeeper constraint uses the Rego policy language to evaluate admission requests, rejecting any pod whose image field does not match the permitted registry prefix. This enforces the registry restriction at admission time, before the workload is persisted to etcd.

  • ✗

    NetworkPolicy to restrict egress to registries

    Why it's wrong here

    NetworkPolicy governs pod network traffic, not admission of images at deployment time. It tempts because blocking egress to unauthorised registries seems to prevent pulls, but images already present or pulled via allowed paths still deploy, so registry enforcement fails.

About these practice questions

One of 845 original CKS practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.