Courseiva
Supply Chain Security →easyMultiple Choice

CKS Supply Chain Security Practice Question

Which tool is commonly used to generate a Software Bill of Materials (SBOM) for a container image?

⚠ Common exam trap

The CKS exam often tests the distinction between tools that generate SBOMs (Syft) and tools that scan for vulnerabilities (Trivy) or sign images (Cosign), leading candidates to confuse Trivy's SBOM capability with its primary vulnerability scanning role.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

syft

Syft is a CLI tool purpose-built for generating Software Bill of Materials (SBOMs) from container images and filesystems. It uses static analysis to extract package metadata (e.g., dpkg, RPM, APK, Python, Node.js) and outputs the SBOM in formats like CycloneDX or SPDX, which are the industry standards for supply chain transparency.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    kubesec

    Why it's wrong here

    Kubesec is a Kubernetes security scanner that statically analyzes resource manifests like Deployments and Pods, scoring them against best practices such as disallowing privileged containers or host network access. It operates entirely on YAML/JSON declarations and never inspects container image layers, package metadata, or filesystem contents. Since generating an SBOM requires enumerating the actual software components inside an image or directory, kubesec lacks the fundamental capability to produce a software bill of materials.

  • ✓

    syft

    Why this is correct

    Syft is a dedicated, purpose-built SBOM generator from Anchore that catalogs packages from container images, OCI layout archives, and directory trees. It supports a broad range of ecosystems — dpkg, RPM, APK, Python, npm, Go modules, Java archives, etc. — and emits standardized formats like SPDX, CycloneDX, and its own custom Syft format. Because its sole mission is to inventory components with precise versions and package URLs, syft is the authoritative and most commonly used tool for generating SBOMs in cloud-native environments.

  • ✗

    trivy

    Why it's wrong here

    Trivy is primarily a vulnerability scanner: it scans container images and filesystems for known CVEs by matching installed package versions against NVD and other databases. Although recent versions include an 'sbom' subcommand that can output SPDX or CycloneDX, that functionality is an auxiliary feature built on top of its scanning engine rather than a comprehensive cataloger. Trivy's SBOM output omits some dependency relationships and metadata that syft captures, so while it can produce a partial SBOM, the dedicated and conventional choice for SBOM generation is syft.

  • ✗

    cosign

    Why it's wrong here

    Cosign is a supply-chain security tool from the sigstore project that cryptographically signs container images and artifacts, and verifies signatures during developer workflows or cluster admission control. It enables keyless signing using Fulcio and transparency logs, and it can also sign an SBOM artifact to authenticate its provenance. However, signing requires an SBOM to already exist; cosign does not analyze images, inspect folders, or enumerate packages, so it has no role in the actual creation of a software bill of materials.

About these practice questions

This CKS question is part of Courseiva's 845-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.