Courseiva
Supply Chain Security →hardMultiple Select

CKS Supply Chain Security Practice Question

Which TWO of the following admission controllers are relevant for supply chain security in Kubernetes?

⚠ Common exam trap

The CKS exam often tests the difference between the purpose-built ImagePolicyWebhook and generic admission webhooks. ValidatingAdmissionWebhook is relevant when used by policy engines such as Kyverno/Gatekeeper to enforce supply chain policies, but MutatingAdmissionWebhook for sidecar injection, AlwaysPullImages, and NodeRestriction are not supply chain security controllers in this context.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

ImagePolicyWebhook

ImagePolicyWebhook (B) is correct because it is the built-in admission controller that forwards pod image decisions to an external image policy service, enabling enforcement of trusted registries, signature verification, and vulnerability policies before a workload is admitted. ValidatingAdmissionWebhook (E) is correct because policy engines such as Kyverno and OPA Gatekeeper use it to validate resources against supply chain rules, for example rejecting images that lack a valid Cosign signature or that come from unapproved registries. MutatingAdmissionWebhook (A) is not the right answer here since its typical use is sidecar injection and defaulting, not supply chain verification. AlwaysPullImages (C) only forces image pulls on every pod start to avoid stale cached images and does not verify provenance or trust. NodeRestriction (D) limits what kubelets can modify on Node and Pod objects, which is a node-security control rather than a supply chain control.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    MutatingAdmissionWebhook (for sidecar injection)

    Why it's wrong here

    MutatingAdmissionWebhook injects sidecars and mutates pod specs; it does not verify image signatures, digests or provenance, so it cannot enforce supply chain integrity. It is tempting because admission webhooks are the extensibility point where policy engines such as Kyverno or Gatekeeper plug in, and those can validate signed images when configured to do so.

  • ✓

    ImagePolicyWebhook

    Why this is correct

    ImagePolicyWebhook is a built-in admission controller that queries an external service to validate image references before pods are admitted. It directly supports supply chain security by blocking images that fail registry or signature policy checks at admission time.

  • ✗

    AlwaysPullImages

    Why it's wrong here

    AlwaysPullImages forces the kubelet to fetch the image from the registry on every pod start, ensuring freshness but not authenticity; a tampered tag still deploys. It is tempting because it prevents stale cached images being reused, which suits shared clusters where image pull policy matters, yet signature verification requires a policy admission controller instead.

  • ✗

    NodeRestriction

    Why it's wrong here

    NodeRestriction limits which fields a kubelet may modify on its own Node and Pod objects, addressing node identity spoofing rather than image provenance or artefact integrity. It is tempting because it hardens the cluster against a compromised node, which is a legitimate control-plane security measure, but supply chain security concerns verifying what images and code reach workloads.

  • ✓

    ValidatingAdmissionWebhook (used by Kyverno/Gatekeeper)

    Why this is correct

    ValidatingAdmissionWebhook is the built-in admission controller that Kyverno and Gatekeeper register against, receiving AdmissionReview requests for policy evaluation. It enables dynamic, policy-driven image validation at admission time, satisfying the supply chain security requirement without hardcoding checks into the API server.

About these practice questions

One of 845 original CKS practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.