CKS Supply Chain Security Practice Question
Which TWO of the following are benefits of using an SBOM (Software Bill of Materials) in supply chain security?
⚠ Common exam trap
A common trap in the CKS exam is confusing the passive inventory role of an SBOM with active security actions or performance improvements. Candidates may think an SBOM directly patches vulnerabilities or speeds up image pulls, but it is merely a list of components that enables other tools to act.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
It helps in identifying known vulnerabilities in dependencies
An SBOM lists all components and dependencies in a software artifact, enabling teams to cross-reference against vulnerability databases (e.g., NVD) to identify known CVEs. This proactive identification is a core supply chain security practice, as mandated by frameworks like SLSA and EO 14028.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
It allows for faster image pulls
Why it's wrong here
Image pull speed is governed by network throughput, registry latency, and the size/compression of image layers; a Software Bill of Materials is an inert metadata document, not part of the layer chain, so it cannot alter transfer mechanics. Even if an SBOM is embedded as an additional layer or attached as an attestation, it would only incrementally increase the payload, never accelerate the download.
- ✓
It helps in identifying known vulnerabilities in dependencies
Why this is correct
An SBOM enumerates every direct and transitive dependency along with its version range, enabling deterministic cross-checks against vulnerability intelligence feeds such as CVE records, OSV entries, or vendor security advisories. This turns an opaque binary artifact into a structured inventory that tools can map to known flaws, so remediation prioritization and impact analysis become reproducible rather than based on guesswork.
- ✓
It ensures license compliance by tracking open source components
Why this is correct
SBOMs such as SPDX or CycloneDX record each component's declared license(s), including multi-licensing and exception cases, which lets organizations automate policy checks against their legal requirements, e.g., avoiding strong copyleft licenses or verifying permissive licenses. This provides an auditable trail for compliance reviews and helps prevent accidental introduction of incompatible third-party code, though it does not by itself grant legal clearance.
- ✗
It reduces the size of the container image
Why it's wrong here
Container image size is determined by the cumulative bytes of filesystem layers, the base OS, binaries, libraries, and any artifacts baked into the layers; an SBOM is a list of metadata, not a runtime dependency. Distributing an SBOM as a separate signed artifact or plugging it into a registry's attestation mechanism leaves the image layers and their hashes untouched, so it cannot reduce compressed or uncompressed image size.
- ✗
It automatically patches vulnerabilities
Why it's wrong here
An SBOM is purely descriptive—it says what components exist and in which versions, but it lacks any executable logic to modify, update, or remove files, and it never interacts with a package manager or container runtime. While SBOMs supply the data that drives scanners and patch automation, the act of patching is a separate process that requires a patching mechanism, orchestrator, or human action; the document itself remains static.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CKS question from scratch — 845 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CKS practice question is part of Courseiva's free CNCF certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CKS exam.