CKS Supply Chain Security Practice Question
Which THREE of the following are valid flags for the 'trivy image' command to output results in different formats?
⚠ Common exam trap
The CKS exam often tests the distinction between Trivy's supported output formats and common but unsupported formats like XML or YAML, exploiting the assumption that any common data serialization format would be valid.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
--format table
The `trivy image` command supports multiple output formats via the `--format` flag. The valid formats include `table`, `sarif`, and `json`, which are explicitly documented in Trivy's CLI help. `table` produces a human-readable summary, `sarif` outputs results in the SARIF (Static Analysis Results Interchange Format) standard, and `json` provides structured data for programmatic consumption.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
--format table
Why this is correct
The --format table flag explicitly selects the default human-readable output format for Trivy. It prints a tabular view with columns such as Library, Vulnerability, Severity, and Installed Version, making it ideal for terminal inspection but unsuitable for automated parsing. Using this flag is redundant if no format is specified, but it is valid and often used for clarity in scripts.
- ✓
--format sarif
Why this is correct
The --format sarif flag outputs results in SARIF (Static Analysis Results Interchange Format), a JSON-based standard for static analysis tools. This enables direct integration with platforms like GitHub Code Scanning or Azure DevOps, which can ingest SARIF to display alerts natively. Trivy's SARIF output includes vulnerability rules, paths, and severities, making it a powerful choice for CI/CD security gates.
- ✗
--format xml
Why it's wrong here
The --format xml flag is invalid because Trivy does not support XML output. Unlike some other vulnerability scanners that offer XML reports, Trivy limits its output formats to table, JSON, Sarif, and template. Attempting to use this flag produces an error indicating an unsupported format, reflecting the industry's shift away from XML in favor of JSON-based interchange.
- ✗
--format yaml
Why it's wrong here
The --format yaml flag is invalid because Trivy does not have a YAML output mode. While YAML is common for Kubernetes manifests and configuration, Trivy deliberately omits it as an output format, offering table, JSON, Sarif, and template instead. Users who need parseable YAML-style output must rely on custom Go templates, as trying --format yaml will fail with an error.
- ✓
--format json
Why this is correct
The --format json flag is a valid output option that produces a structured, machine-readable representation of scan results. The JSON schema includes metadata such as target, type, and schema version, along with detailed vulnerability entries containing severity, CVSS scores, and fixed versions. This format is essential for CI/CD pipelines, enabling tools like jq to filter results and enforce security policies.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CKS question from scratch — 845 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.