CKS Supply Chain Security Practice Question
Which THREE of the following are best practices for securing the software supply chain in a CI/CD pipeline?
⚠ Common exam trap
CNCF-CKS often tests the misconception that a larger base image is more secure because it includes more libraries, when in fact minimal images (e.g., distroless or scratch) reduce the attack surface and are a supply chain best practice.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Sign images with Cosign after building
Option A is correct because signing images with Cosign (part of the Sigstore project) after building produces a cryptographic signature that allows downstream consumers and admission controllers to verify image provenance and integrity, preventing tampered or unauthorized images from being deployed. Option B is correct because generating a Software Bill of Materials (SBOM) for each image provides a machine-readable inventory of components and dependencies, enabling rapid vulnerability triage and license/compliance auditing when new CVEs emerge. Option C is correct because scanning container images with Trivy detects known CVEs in OS packages and application dependencies before the image is promoted, catching vulnerabilities early in the CI/CD pipeline. Option D is incorrect because best practice favors minimal base images (e.g., distroless or Alpine) to reduce attack surface, not bloated images with unnecessary libraries. Option E is incorrect because storing secrets in a Dockerfile as build args embeds them in image layers and build history, exposing them to anyone who can pull the image; secrets should instead come from a vault or secret manager at runtime.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Sign images with Cosign after building
Why this is correct
Cosign signing produces a verifiable signature binding the image digest to a trusted identity, enabling admission policies to reject unsigned artefacts. This satisfies the supply-chain requirement by proving provenance and integrity from build through deployment.
- ✓
Generate an SBOM for each image
Why this is correct
Generating an SBOM per image records every component and dependency, giving the pipeline the visibility needed to detect vulnerable or malicious packages. This directly satisfies the stem's supply-chain security requirement by enabling rapid identification of affected artefacts when a new CVE emerges, supporting provenance and audit across builds.
- ✓
Scan container images for vulnerabilities using Trivy
Why this is correct
Trivy scans image layers against CVE databases, detecting vulnerable OS packages and language dependencies before deployment. Integrating it into the pipeline catches known vulnerabilities at build time, satisfying the supply-chain requirement to prevent flawed artefacts reaching production.
- ✗
Use a non-minimal base image to ensure all libraries are available
Why it's wrong here
A non-minimal base image ships unnecessary packages, enlarging the attack surface and CVE exposure that image scanning must then remediate. It is tempting when teams want preinstalled tooling, yet minimal or distroless images are the supply-chain hardening choice; extra libraries belong in a separate build stage.
- ✗
Store secrets in the Dockerfile as build args
Why it's wrong here
Build args are recorded in image history and metadata, so any registry reader can recover the secret; they are not a secrets mechanism. It is tempting because ARG values are easy to pass at build time, but runtime injection from a vault or Kubernetes Secret is the correct pattern.
Go deeper
Related to this question
Learn chapter
Microservice Vulnerabilities: Pod Security Standards
Key term
Admission Controllers
Admission controllers are plugins that intercept and process requests to the Kubernetes API server after authentication and authorization, but before the request is persisted, allowing policies to be enforced on objects being created, modified, or deleted.
Key term
Image Signing and Verification
Image signing and verification is the process of digitally signing a container image to prove its origin and integrity, and then checking that signature before using the image to ensure it was not tampered with.
About these practice questions
Courseiva writes every CKS question from scratch — 845 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.