Courseiva
Supply Chain Security →mediumMultiple Select

CKS Supply Chain Security Practice Question

Which THREE of the following are best practices for securing the software supply chain in a CI/CD pipeline?

⚠ Common exam trap

CNCF-CKS often tests the misconception that a larger base image is more secure because it includes more libraries, when in fact minimal images (e.g., distroless or scratch) reduce the attack surface and are a supply chain best practice.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Sign images with Cosign after building

Option A is correct because signing images with Cosign (part of the Sigstore project) after building produces a cryptographic signature that allows downstream consumers and admission controllers to verify image provenance and integrity, preventing tampered or unauthorized images from being deployed. Option B is correct because generating a Software Bill of Materials (SBOM) for each image provides a machine-readable inventory of components and dependencies, enabling rapid vulnerability triage and license/compliance auditing when new CVEs emerge. Option C is correct because scanning container images with Trivy detects known CVEs in OS packages and application dependencies before the image is promoted, catching vulnerabilities early in the CI/CD pipeline. Option D is incorrect because best practice favors minimal base images (e.g., distroless or Alpine) to reduce attack surface, not bloated images with unnecessary libraries. Option E is incorrect because storing secrets in a Dockerfile as build args embeds them in image layers and build history, exposing them to anyone who can pull the image; secrets should instead come from a vault or secret manager at runtime.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Sign images with Cosign after building

    Why this is correct

    Cosign signing produces a verifiable signature binding the image digest to a trusted identity, enabling admission policies to reject unsigned artefacts. This satisfies the supply-chain requirement by proving provenance and integrity from build through deployment.

  • ✓

    Generate an SBOM for each image

    Why this is correct

    Generating an SBOM per image records every component and dependency, giving the pipeline the visibility needed to detect vulnerable or malicious packages. This directly satisfies the stem's supply-chain security requirement by enabling rapid identification of affected artefacts when a new CVE emerges, supporting provenance and audit across builds.

  • ✓

    Scan container images for vulnerabilities using Trivy

    Why this is correct

    Trivy scans image layers against CVE databases, detecting vulnerable OS packages and language dependencies before deployment. Integrating it into the pipeline catches known vulnerabilities at build time, satisfying the supply-chain requirement to prevent flawed artefacts reaching production.

  • ✗

    Use a non-minimal base image to ensure all libraries are available

    Why it's wrong here

    A non-minimal base image ships unnecessary packages, enlarging the attack surface and CVE exposure that image scanning must then remediate. It is tempting when teams want preinstalled tooling, yet minimal or distroless images are the supply-chain hardening choice; extra libraries belong in a separate build stage.

  • ✗

    Store secrets in the Dockerfile as build args

    Why it's wrong here

    Build args are recorded in image history and metadata, so any registry reader can recover the secret; they are not a secrets mechanism. It is tempting because ARG values are easy to pass at build time, but runtime injection from a vault or Kubernetes Secret is the correct pattern.

Go deeper

Related to this question

About these practice questions

Courseiva writes every CKS question from scratch — 845 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.