Courseiva
Supply Chain Security →easyMultiple Choice

CKS Supply Chain Security Practice Question

Which tool is specifically designed to generate a Software Bill of Materials (SBOM) for container images?

⚠ Common exam trap

CNCF-CKS often tests the distinction between tools that generate SBOMs (Syft) and tools that scan for vulnerabilities (Trivy) or sign images (Cosign), leading candidates to confuse Trivy's vulnerability scanning capability with SBOM generation.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Syft

Syft is an open-source CLI tool developed by Anchore specifically for generating Software Bill of Materials (SBOMs) from container images and filesystems. It uses static analysis to catalog packages, libraries, and dependencies in formats such as CycloneDX and SPDX, making it the correct choice for this purpose.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Checkov

    Why it's wrong here

    Checkov is a static analysis tool that scans infrastructure-as-code templates for misconfigurations; it does not generate an SBOM from container image layers. It would be correct when validating Terraform, CloudFormation or Kubernetes manifests against security policies before deployment.

  • ✗

    Cosign

    Why it's wrong here

    Cosign signs and verifies container images, anchoring supply-chain integrity through cryptographic signatures and attestations. It does not enumerate packages into an SBOM; that requires a scanner such as Syft. Cosign would be correct when the requirement is proving an image's provenance or signature before deployment.

  • ✓

    Syft

    Why this is correct

    Syft scans container image layers and filesystem contents to produce an SBOM listing installed packages and their versions, satisfying the requirement to catalogue image components. Unlike general vulnerability scanners, its purpose is SBOM generation itself, outputting SPDX or CycloneDX formats directly from image references.

  • ✗

    Trivy

    Why it's wrong here

    Trivy does generate SBOMs, but its primary design is vulnerability and misconfiguration scanning; SBOM output is a secondary feature. The question asks for a tool specifically designed for SBOM generation, where Syft is the dedicated choice. Trivy would be correct if the requirement were detecting CVEs in images.

About these practice questions

This CKS question is part of Courseiva's 845-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.