CKS Supply Chain Security Practice Question
Which THREE of the following can be used to enforce policies on container images in a Kubernetes cluster? (Select 3)
⚠ Common exam trap
It's easy for candidates to confuse vulnerability scanning tools (like Trivy) with policy enforcement engines, or assume kubectl can enforce policies via commands, when in fact only admission controllers or policy engines like Kyverno, OPA/Gatekeeper, and ImagePolicyWebhook can enforce image policies at the cluster level.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Kyverno
Kyverno (A) is correct because it is a Kubernetes-native policy engine that runs as an admission controller and can validate, mutate, and generate resources, including enforcing rules on container images (e.g., allowed registries, required signatures, or tag restrictions) via ClusterPolicy/Policy resources. ImagePolicyWebhook (B) is correct because it is a built-in Kubernetes admission controller plugin that sends image admission requests to an external HTTP webhook, which can approve or reject pods based on image policy decisions. OPA/Gatekeeper (D) is correct because Gatekeeper deploys Open Policy Agent as a validating admission webhook in Kubernetes, using ConstraintTemplates and Constraints to enforce policies such as restricting container image registries or requiring trusted images. Trivy (C) is not correct here because it is a vulnerability and misconfiguration scanner for images and filesystems, not an admission-time policy enforcement mechanism. kubectl (E) is not correct because it is the Kubernetes command-line client for interacting with the API server, not a policy engine or admission controller.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Kyverno
Why this is correct
Kyverno is a Kubernetes-native admission controller that validates and mutates resources against policies written as YAML, so it can block non-compliant container images at admission time without requiring a separate policy language or external agent.
- ✓
ImagePolicyWebhook
Why this is correct
ImagePolicyWebhook is a built-in Kubernetes admission controller that queries an external HTTPS endpoint before admitting a pod, letting that service reject images failing your policy. It satisfies the stem's enforcement requirement by blocking non-compliant images at admission time, rather than merely scanning or reporting afterwards.
- ✗
Trivy
Why it's wrong here
Trivy scans images for known CVEs and misconfigurations, reporting findings rather than blocking a pod from starting. It is tempting because scanning is a genuine part of image security, but detection is not enforcement; only an admission controller or policy engine can deny the workload at creation time.
- ✓
OPA/Gatekeeper
Why this is correct
OPA/Gatekeeper enforces policies at admission time via validating webhooks, rejecting non-compliant pods before they run. Its Rego constraint templates can inspect image registries, tags and digests, satisfying the stem's requirement to enforce container image policies cluster-wide.
- ✗
kubectl
Why it's wrong here
kubectl is the client that submits API requests; it cannot intercept or reject image pulls, so no policy is enforced. It is tempting because admission controllers and validating webhooks are configured through kubectl, but the enforcement itself is performed by the API server's admission chain, not the CLI.
Go deeper
Related to this question
Learn chapter
Supply Chain Security: Container Image Security
Key term
Image Scanning
Image scanning is the automated process of inspecting container images for known vulnerabilities, misconfigurations, and malware before they are deployed into production environments.
Key term
Node Restriction
A Kubernetes admission controller that limits what a kubelet can modify on its own node to prevent privilege escalation and unauthorized access.
About these practice questions
One of 845 original CKS practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.