Courseiva
Supply Chain Security →mediumMultiple Choice

CKS Supply Chain Security Practice Question

Which tool can be used to perform static analysis of Kubernetes manifests for security issues?

⚠ Common exam trap

Watch out — candidates often confuse general vulnerability scanners (like Trivy) or image signing tools (like Cosign) with dedicated Kubernetes manifest static analysis tools, leading them to pick a tool that is not specifically designed for scanning YAML security configurations.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

kubesec

Kubesec is a static analysis tool specifically designed to evaluate Kubernetes resource manifests against a set of built-in security best practices. It scans YAML or JSON manifests for common misconfigurations such as running containers as root, missing resource limits, or insecure capability assignments, and returns a risk score. This makes it the correct choice for static analysis of Kubernetes manifests for security issues.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    syft

    Why it's wrong here

    Syft is an SBOM (Software Bill of Materials) generation tool by Anchore that scans container images and filesystems to list packages and dependencies. It does not perform static analysis of Kubernetes manifests or workloads, so it cannot evaluate security misconfigurations like privileged containers or RBAC issues. Syft focuses on inventorying components for vulnerability management, not on assessing the manifest's security posture.

  • ✗

    cosign

    Why it's wrong here

    Cosign is a tool for content signing and verification of container images, part of the Sigstore project. It allows you to digitally sign image digests and verify signatures to ensure image integrity and provenance, but it does not parse or analyze Kubernetes YAML manifests for security risks. Cosign addresses supply chain security rather than static configuration analysis.

  • ✓

    kubesec

    Why this is correct

    Kubesec is a static analysis tool that evaluates Kubernetes resource manifests against a set of security best practice rules, scoring them and flagging risks such as running as root, privilege escalation, and insecure capabilities. It returns a risk score and provides remediation advice directly from the manifest, making it suitable for CI/CD integration. This is exactly the capability needed for static analysis of Kubernetes manifests, unlike the other tools listed.

  • ✗

    trivy

    Why it's wrong here

    Trivy is a comprehensive vulnerability scanner for container images, file systems, and git repositories, also providing IaC misconfiguration scanning. However, when used in Kubernetes context, its primary static analysis is on container images and infrastructure-as-code templates (e.g., Terraform, CloudFormation) rather than specifically evaluating live manifest security constructs like PodSecurityPolicies. Trivy can scan Kubernetes YAMLs with its config subcommand, but its most common and primary role remains image vulnerability detection, which does not match the dedicated manifest analysis of kubesec.

About these practice questions

This CKS question is part of Courseiva's 845-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.