CKS Supply Chain Security Practice Question
Which TWO of the following admission controllers are relevant for supply chain security in Kubernetes?
⚠ Common exam trap
The CKS exam often tests the difference between the purpose-built ImagePolicyWebhook and generic admission webhooks. ValidatingAdmissionWebhook is relevant when used by policy engines such as Kyverno/Gatekeeper to enforce supply chain policies, but MutatingAdmissionWebhook for sidecar injection, AlwaysPullImages, and NodeRestriction are not supply chain security controllers in this context.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
ImagePolicyWebhook
ImagePolicyWebhook (B) is correct because it is the built-in admission controller that forwards pod image decisions to an external image policy service, enabling enforcement of trusted registries, signature verification, and vulnerability policies before a workload is admitted. ValidatingAdmissionWebhook (E) is correct because policy engines such as Kyverno and OPA Gatekeeper use it to validate resources against supply chain rules, for example rejecting images that lack a valid Cosign signature or that come from unapproved registries. MutatingAdmissionWebhook (A) is not the right answer here since its typical use is sidecar injection and defaulting, not supply chain verification. AlwaysPullImages (C) only forces image pulls on every pod start to avoid stale cached images and does not verify provenance or trust. NodeRestriction (D) limits what kubelets can modify on Node and Pod objects, which is a node-security control rather than a supply chain control.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
MutatingAdmissionWebhook (for sidecar injection)
Why it's wrong here
MutatingAdmissionWebhook injects sidecars and mutates pod specs; it does not verify image signatures, digests or provenance, so it cannot enforce supply chain integrity. It is tempting because admission webhooks are the extensibility point where policy engines such as Kyverno or Gatekeeper plug in, and those can validate signed images when configured to do so.
- ✓
ImagePolicyWebhook
Why this is correct
ImagePolicyWebhook is a built-in admission controller that queries an external service to validate image references before pods are admitted. It directly supports supply chain security by blocking images that fail registry or signature policy checks at admission time.
- ✗
AlwaysPullImages
Why it's wrong here
AlwaysPullImages forces the kubelet to fetch the image from the registry on every pod start, ensuring freshness but not authenticity; a tampered tag still deploys. It is tempting because it prevents stale cached images being reused, which suits shared clusters where image pull policy matters, yet signature verification requires a policy admission controller instead.
- ✗
NodeRestriction
Why it's wrong here
NodeRestriction limits which fields a kubelet may modify on its own Node and Pod objects, addressing node identity spoofing rather than image provenance or artefact integrity. It is tempting because it hardens the cluster against a compromised node, which is a legitimate control-plane security measure, but supply chain security concerns verifying what images and code reach workloads.
- ✓
ValidatingAdmissionWebhook (used by Kyverno/Gatekeeper)
Why this is correct
ValidatingAdmissionWebhook is the built-in admission controller that Kyverno and Gatekeeper register against, receiving AdmissionReview requests for policy evaluation. It enables dynamic, policy-driven image validation at admission time, satisfying the supply chain security requirement without hardcoding checks into the API server.
Go deeper
Related to this question
Learn chapter
Supply Chain Security: Container Image Security
Key term
OPA Gatekeeper
OPA Gatekeeper is a Kubernetes admission controller that enforces custom security and compliance policies on resources before they are created or updated in a cluster.
Key term
Node Restriction
A Kubernetes admission controller that limits what a kubelet can modify on its own node to prevent privilege escalation and unauthorized access.
About these practice questions
One of 845 original CKS practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.