Courseiva
Supply Chain Security →mediumMultiple Choice

CKS Supply Chain Security Practice Question

Which tool can generate an SBOM for a container image?

⚠ Common exam trap

Test-takers frequently confuse Trivy (a vulnerability scanner that can also output SBOMs) with Syft (a dedicated SBOM generator), but the CKS exam expects you to know the primary purpose of each tool in the CNCF supply chain security toolkit.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Syft

Syft is a CLI tool specifically designed to generate a Software Bill of Materials (SBOM) for container images and filesystems. It scans the image layers and package managers (e.g., APT, RPM, pip, npm) to produce an SBOM in formats like CycloneDX or SPDX, directly addressing the question's requirement.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Trivy

    Why it's wrong here

    Trivy is predominantly a vulnerability scanner that checks container images and filesystems for known CVEs. Although recent versions introduced experimental SBOM export (e.g., trivy image --format cyclonedx), that is not its core focus. For dedicated, direct SBOM generation from an image, Syft is the canonical open-source tool.

  • ✗

    Cosign

    Why it's wrong here

    Cosign, part of the Sigstore project, is designed for signing and verifying container images and software artifacts. It does not inspect image contents to build an SBOM; instead, it can sign an SBOM or attach one as an in-toto attestation. Generating an SBOM is outside Cosign's scope.

  • ✗

    Kubescape

    Why it's wrong here

    Kubescape is a Kubernetes security scanner that evaluates clusters, manifests, and Helm charts against compliance frameworks such as NSA/CISA. It operates on configuration and runtime data, not container image internals, so it cannot enumerate packages or dependencies to produce an SBOM.

  • ✓

    Syft

    Why this is correct

    Syft is a purpose-built SBOM generator from Anchore that scans container images and filesystems to inventory packages, libraries, and dependencies. It outputs standard formats like CycloneDX, SPDX, and Syft JSON, making it the definitive tool for converting an image into a software bill of materials.

About these practice questions

One of 845 original CKS practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.