CKS Supply Chain Security Practice Question
Which three of the following are valid ways to enforce supply chain security in a Kubernetes cluster? (Select THREE.)
⚠ Common exam trap
The CKS exam often tests the distinction between resource management (ResourceQuota) and security controls (image verification), and the trap here is that candidates confuse limiting pull counts with enforcing image trust, or assume NetworkPolicy can filter by registry identity when it only works at the IP/port level.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use Cosign to sign images and configure verification in the cluster
A is correct because Cosign is a tool for signing container images using cryptographic keys, and by integrating it with Kubernetes admission controllers (e.g., via the Cosign webhook or Kyverno), the cluster can verify image signatures before allowing a pod to run. This ensures that only images signed by trusted parties are deployed, directly enforcing supply chain integrity.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Use Cosign to sign images and configure verification in the cluster
Why this is correct
Cosign lets you sign container images with a private key or use sigstore's keyless flow, then store the signature in a registry alongside the image. To enforce in the cluster, you pair Cosign with an admission controller such as the sigstore policy-controller, which verifies the signature on the image manifest during pod creation. Only images signed by trusted keys are admitted, blocking tampered or unofficial images directly at the API server.
- ✓
Configure ImagePolicyWebhook to reject images from untrusted registries
Why this is correct
ImagePolicyWebhook is a Kubernetes admission controller that sends each image reference to an external HTTP(S) webhook, which returns an admission decision based on its own trust rules. The webhook can reject images from registries not on an allowlist, or that fail custom checks like digest pinning or scorecard ratings. Because it runs synchronously before a pod is persisted, it enforces registry trust centrally without modifying manifests.
- ✗
Use ResourceQuota to limit the number of images that can be pulled
Why it's wrong here
ResourceQuota is a namespace-level control that limits aggregate consumption of resources such as CPU, memory, persistent volume claims, and the number of particular object types. It has no concept of container image registry, tag, or digest, so it cannot evaluate whether an image comes from an untrusted source. Attempting to use quotas for image provenance is fundamentally misaligned, as they only bound quantities and never inspect image metadata.
- ✗
Use NetworkPolicy to block egress traffic to unknown registries
Why it's wrong here
NetworkPolicy defines L3/L4 rules for pod traffic, filtering by IP, CIDR, port, and labels, and is enforced by the CNI plugin on the pod's network paths. Even if you blocked egress to known registry IPs, the kubelet's image pull does not traverse the pod network; it runs in the node's runtime context. Thus it neither validates image content nor reliably prevents pulls from unknown registries, making it ineffective for provenance enforcement.
- ✓
Use OPA/Gatekeeper to enforce that container images come from an allowed list of registries
Why this is correct
Gatekeeper extends Kubernetes with validating admission via OPA Rego policies, evaluated before objects are persisted. A constraint template can inspect the `image` field in `spec.containers` and apply a regex allowlist over the registry prefix, such as requiring `gcr.io/`. If the image string doesn't match, the pod is rejected with a clear message, enabling cluster-wide provenance rules without external services.
Go deeper
Related to this question
Learn chapter
Cluster Setup: Secure Configuration and Best Practices
Key term
Admission Controllers
Admission controllers are plugins that intercept and process requests to the Kubernetes API server after authentication and authorization, but before the request is persisted, allowing policies to be enforced on objects being created, modified, or deleted.
Key term
Image Signing and Verification
Image signing and verification is the process of digitally signing a container image to prove its origin and integrity, and then checking that signature before using the image to ensure it was not tampered with.
About these practice questions
Courseiva writes every CKS question from scratch — 845 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.