CKS Supply Chain Security Practice Question
Which tool is commonly used to generate a Software Bill of Materials (SBOM) for a container image?
⚠ Common exam trap
The CKS exam often tests the distinction between tools that generate SBOMs (Syft) and tools that scan for vulnerabilities (Trivy) or sign images (Cosign), leading candidates to confuse Trivy's SBOM capability with its primary vulnerability scanning role.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
syft
Syft is a CLI tool purpose-built for generating Software Bill of Materials (SBOMs) from container images and filesystems. It uses static analysis to extract package metadata (e.g., dpkg, RPM, APK, Python, Node.js) and outputs the SBOM in formats like CycloneDX or SPDX, which are the industry standards for supply chain transparency.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
kubesec
Why it's wrong here
Kubesec is a Kubernetes security scanner that statically analyzes resource manifests like Deployments and Pods, scoring them against best practices such as disallowing privileged containers or host network access. It operates entirely on YAML/JSON declarations and never inspects container image layers, package metadata, or filesystem contents. Since generating an SBOM requires enumerating the actual software components inside an image or directory, kubesec lacks the fundamental capability to produce a software bill of materials.
- ✓
syft
Why this is correct
Syft is a dedicated, purpose-built SBOM generator from Anchore that catalogs packages from container images, OCI layout archives, and directory trees. It supports a broad range of ecosystems — dpkg, RPM, APK, Python, npm, Go modules, Java archives, etc. — and emits standardized formats like SPDX, CycloneDX, and its own custom Syft format. Because its sole mission is to inventory components with precise versions and package URLs, syft is the authoritative and most commonly used tool for generating SBOMs in cloud-native environments.
- ✗
trivy
Why it's wrong here
Trivy is primarily a vulnerability scanner: it scans container images and filesystems for known CVEs by matching installed package versions against NVD and other databases. Although recent versions include an 'sbom' subcommand that can output SPDX or CycloneDX, that functionality is an auxiliary feature built on top of its scanning engine rather than a comprehensive cataloger. Trivy's SBOM output omits some dependency relationships and metadata that syft captures, so while it can produce a partial SBOM, the dedicated and conventional choice for SBOM generation is syft.
- ✗
cosign
Why it's wrong here
Cosign is a supply-chain security tool from the sigstore project that cryptographically signs container images and artifacts, and verifies signatures during developer workflows or cluster admission control. It enables keyless signing using Fulcio and transparency logs, and it can also sign an SBOM artifact to authenticate its provenance. However, signing requires an SBOM to already exist; cosign does not analyze images, inspect folders, or enumerate packages, so it has no role in the actual creation of a software bill of materials.
Go deeper
Related to this question
About these practice questions
This CKS question is part of Courseiva's 845-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.