Courseiva
Supply Chain Security →hardMultiple Select

CKS Supply Chain Security Practice Question

Which THREE of the following can be used to enforce policies on container images in a Kubernetes cluster? (Select 3)

⚠ Common exam trap

It's easy for candidates to confuse vulnerability scanning tools (like Trivy) with policy enforcement engines, or assume kubectl can enforce policies via commands, when in fact only admission controllers or policy engines like Kyverno, OPA/Gatekeeper, and ImagePolicyWebhook can enforce image policies at the cluster level.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Kyverno

Kyverno (A) is correct because it is a Kubernetes-native policy engine that runs as an admission controller and can validate, mutate, and generate resources, including enforcing rules on container images (e.g., allowed registries, required signatures, or tag restrictions) via ClusterPolicy/Policy resources. ImagePolicyWebhook (B) is correct because it is a built-in Kubernetes admission controller plugin that sends image admission requests to an external HTTP webhook, which can approve or reject pods based on image policy decisions. OPA/Gatekeeper (D) is correct because Gatekeeper deploys Open Policy Agent as a validating admission webhook in Kubernetes, using ConstraintTemplates and Constraints to enforce policies such as restricting container image registries or requiring trusted images. Trivy (C) is not correct here because it is a vulnerability and misconfiguration scanner for images and filesystems, not an admission-time policy enforcement mechanism. kubectl (E) is not correct because it is the Kubernetes command-line client for interacting with the API server, not a policy engine or admission controller.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Kyverno

    Why this is correct

    Kyverno is a Kubernetes-native admission controller that validates and mutates resources against policies written as YAML, so it can block non-compliant container images at admission time without requiring a separate policy language or external agent.

  • ✓

    ImagePolicyWebhook

    Why this is correct

    ImagePolicyWebhook is a built-in Kubernetes admission controller that queries an external HTTPS endpoint before admitting a pod, letting that service reject images failing your policy. It satisfies the stem's enforcement requirement by blocking non-compliant images at admission time, rather than merely scanning or reporting afterwards.

  • ✗

    Trivy

    Why it's wrong here

    Trivy scans images for known CVEs and misconfigurations, reporting findings rather than blocking a pod from starting. It is tempting because scanning is a genuine part of image security, but detection is not enforcement; only an admission controller or policy engine can deny the workload at creation time.

  • ✓

    OPA/Gatekeeper

    Why this is correct

    OPA/Gatekeeper enforces policies at admission time via validating webhooks, rejecting non-compliant pods before they run. Its Rego constraint templates can inspect image registries, tags and digests, satisfying the stem's requirement to enforce container image policies cluster-wide.

  • ✗

    kubectl

    Why it's wrong here

    kubectl is the client that submits API requests; it cannot intercept or reject image pulls, so no policy is enforced. It is tempting because admission controllers and validating webhooks are configured through kubectl, but the enforcement itself is performed by the API server's admission chain, not the CLI.

About these practice questions

One of 845 original CKS practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.