CKS Supply Chain Security Practice Question
Which tool can generate an SBOM for a container image?
⚠ Common exam trap
Test-takers frequently confuse Trivy (a vulnerability scanner that can also output SBOMs) with Syft (a dedicated SBOM generator), but the CKS exam expects you to know the primary purpose of each tool in the CNCF supply chain security toolkit.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Syft
Syft is a CLI tool specifically designed to generate a Software Bill of Materials (SBOM) for container images and filesystems. It scans the image layers and package managers (e.g., APT, RPM, pip, npm) to produce an SBOM in formats like CycloneDX or SPDX, directly addressing the question's requirement.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Trivy
Why it's wrong here
Trivy is predominantly a vulnerability scanner that checks container images and filesystems for known CVEs. Although recent versions introduced experimental SBOM export (e.g., trivy image --format cyclonedx), that is not its core focus. For dedicated, direct SBOM generation from an image, Syft is the canonical open-source tool.
- ✗
Cosign
Why it's wrong here
Cosign, part of the Sigstore project, is designed for signing and verifying container images and software artifacts. It does not inspect image contents to build an SBOM; instead, it can sign an SBOM or attach one as an in-toto attestation. Generating an SBOM is outside Cosign's scope.
- ✗
Kubescape
Why it's wrong here
Kubescape is a Kubernetes security scanner that evaluates clusters, manifests, and Helm charts against compliance frameworks such as NSA/CISA. It operates on configuration and runtime data, not container image internals, so it cannot enumerate packages or dependencies to produce an SBOM.
- ✓
Syft
Why this is correct
Syft is a purpose-built SBOM generator from Anchore that scans container images and filesystems to inventory packages, libraries, and dependencies. It outputs standard formats like CycloneDX, SPDX, and Syft JSON, making it the definitive tool for converting an image into a software bill of materials.
Go deeper
Related to this question
About these practice questions
One of 845 original CKS practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.